due now

profileanniej78
chapter_5.docx

CHAPTER 5 LEGAL LIABILITY

LEARNING OBJECTIVES

After studying this chapter, you should be able to

· 5-1 Understand the litigious environment in which CPAs practice.

· 5-2 Explain why the failure of financial statement users to differentiate among business failure, audit failure, and audit risk has resulted in lawsuits.

· 5-3 Use the primary legal concepts and terms concerning accountants’ liability as a basis for studying legal liability of auditors.

· 5-4 Describe accountants’ liability to clients and related defenses.

· 5-5 Describe accountants’ liability to third parties under common law and related defenses.

· 5-6 Describe accountants’ civil liability under the federal securities laws and related defenses.

· 5-7 Specify what constitutes criminal liability for accountants.

· 5-8 Describe how the profession and individual CPAs can reduce the threat of litigation.

It Takes The Net Profit From Many Audits To Offset The Cost Of One Lawsuit

Orange & Rankle, a CPA firm in San Jose, audited a small high-tech client that developed software. A significant portion of the client’s capital was provided by a syndicate of 40 limited partners. The owners of these interests, including several lawyers, were knowledgeable business and professional people.

Orange & Rankle audited the company for 4 consecutive years, from its inception, for an average annual fee of approximately $66,000. The audits were well done by competent auditors. It was clear to the firm and to others who subsequently reviewed the audits that they complied with auditing standards in every way.

In the middle of the fifth year of the company’s existence, it became apparent that the marketing plan it had developed was overly optimistic and the company was going to require additional capital or a significant strategy change. The limited partners were polled and refused to provide the capital. The company folded its tent and filed bankruptcy. The limited partners lost their investment in the company. They subsequently filed a lawsuit against all parties involved in the enterprise, including the auditors.

Over the next several years, the auditors proceeded through the process of preparing to defend themselves in the lawsuit. They went through complete discovery, hired an expert witness on auditing-related issues, filed motions, and so forth. They attempted a settlement at various times, but the plaintiffs would not agree to a reasonable amount. Finally, during the second day of trial, the plaintiffs settled for a nominal amount.

It was clear that the plaintiffs knew the auditors bore no fault but kept them in the suit anyway. The total out-of-pocket cost to the audit firm was $5 million, not to mention personnel time, possible damage to their reputation, and general stress and strain. Thus, the cost of this suit, in which the auditors were completely innocent, was more than 75 times the average annual audit fee earned from this client.

As the auditors at Orange & Rankle learned the hard way, legal liability and its consequences are significant. Although firms have insurance to help alleviate the impact of assessed damages, the premiums are high and the policies available to the firms require large deductibles. The amount of these deductibles is such that large firms are essentially self-insured for losses of many millions of dollars.

This chapter on legal liability and the preceding one on professional ethics highlight the environment in which CPAs operate. These chapters provide an overview of the importance of protecting the profession’s reputation of high ethical standards, highlight consequences accountants face when others believe they have failed to live up to those standards, and show how CPAs can be held legally liable for the professional services they provide.

In this chapter we focus on legal liability for CPAs both on a conceptual level and in terms of specific legal suits that have been filed against CPAs. We also discuss actions available to the profession and individual practitioners to minimize liability while, at the same time, maintaining high ethical and professional standards and meeting the needs of society.

CHANGED LEGAL ENVIRONMENT

OBJECTIVE 5-1

Understand the litigious environment in which CPAs practice.

Professionals have always been required to provide a reasonable level of care while performing work for those they serve. Under common law, audit professionals have a responsibility to fulfill implied or expressed contracts with clients. Should auditors fail to provide the services or not exercise due care in their performance, they are liable to their clients for negligence and/or breach of contract, and, in certain circumstances, to parties other than their clients.

Although the criteria for legal actions against auditors by third parties vary by state, the auditor generally owes a duty of care to third parties who are part of a limited group of persons whose reliance is “foreseen” by the auditor. In addition to common law liability, auditors may be held liable to third parties under statutory law. The Securities Act of 1933, the Securities Exchange Act of 1934, and the Sarbanes–Oxley Act contain provisions that serve as a basis for legal action against auditors. In rare cases, auditors have even been held liable for criminal acts. A criminal conviction against an auditor can result when plaintiffs demonstrate that the auditor intended to deceive or harm others.

Despite efforts by the profession to address legal liability of CPAs, both the number of lawsuits and sizes of awards to plaintiffs remain high, including suits involving third parties under both common law and the federal securities acts. No simple reasons explain this trend, but the following factors are major contributors:

· • Growing awareness of the responsibilities of public accountants by users of financial statements

· • An increased consciousness on the part of the Securities and Exchange Commission (SEC) for its responsibility for protecting investors’ interests

· • The complexity of auditing and accounting functions caused by the increasing size of businesses, the globalization of business, and the complexities of business operations

· • The tendency of society to accept lawsuits by injured parties against anyone who might be able to provide compensation, regardless of who was at fault, coupled with the joint and several liability doctrine (often called the deep-pocket concept of liability)

· • Large civil court judgments against CPA firms awarded in a few cases, encouraging attorneys to provide legal services on a contingent-fee basis, which offers the injured party a potential gain when the suit is successful, but minimal losses when it is not

· • Many CPA firms being willing to settle legal problems out of court in an attempt to avoid costly legal fees and adverse publicity, rather than pursuing resolution through the judicial process

· • The difficulty judges and jurors have understanding and interpreting technical accounting and auditing matters

INTERNATIONAL AFFILIATIONS BRING LEGAL EXPOSURE

In the wake of a major accounting fraud in 2003 that exceeded $9 billion at Italian dairy giant Parmalat, CPA firms are reviewing the structure of their international affiliations to protect themselves from legal exposure for the actions of their international affiliates. Italy’s Grant Thornton SpA, a small member firm of Grant Thornton International, was the accounting firm most directly associated with the accounting scandal. The Italian member firm of Deloitte International was also involved in the audit of Parmalat. Following disclosure of the fraud and alleged audit deficiencies, Grant Thornton International expelled its Italian affiliate. Grant Thornton also declared that the fraud occurred only within the Italian affiliate, and that it should not be legally liable for Grant Thornton SpA’s actions. However, Grant Thornton and Deloitte International, as well as their U.S. member firms, were forced to defend themselves in lawsuits related to Parmalat.

The legal concept that makes one party potentially responsible for the conduct of another is known as “vicarious liability.” In response, both the International Federation of Accountants (IFAC) and AICPA have taken actions to more clearly set out to define a “network” compared to an “association” as it relates to accounting firms. An association ensures strict independence among the member firms, and does not have a common naming structure or operating manuals. In contrast, a network structure includes common ownership or control, and does allow for common naming and operating procedures.

Sources: Adapted from 1. Kevin Mead, “Find the Membership Group that’s Right for Your Firm,” Accounting Today (July 21, 2008) ( www.webcpa.com );2. Richard I. Miller, “Liability for Someone Else’s Sins: The Risks of Accounting Firm Alliances,” Journal of Accountancy (December 2006) pp. 30–32.

Litigation costs for accountants are a concern because they are borne by all members of society. In recent years, legislative efforts have attempted to control litigation costs by discouraging nonmeritorious lawsuits and by bringing damages more in line with relative fault. Nevertheless, accountants’ liability remains burden some and is a major consideration in the conduct of a CPA firm’s professional practice.

DISTINGUISHING BUSINESS FAILURE, AUDIT FAILURE, AND AUDIT RISK

OBJECTIVE 5-2

Explain why the failure of financial statement users to differentiate among business failure, audit failure, and audit risk has resulted in lawsuits.

Many accounting and legal professionals believe that a major cause of lawsuits against CPA firms is financial statement users’ lack of understanding of two concepts:

· 1. The difference between a business failure and an audit failure

· 2. The difference between an audit failure and audit risk

business failure  occurs when a business is unable to repay its lenders or meet the expectations of its investors because of economic or business conditions, such as a recession, poor management decisions, or unexpected competition in the industry.  Audit failure  occurs when the auditor issues an incorrect audit opinion because it failed to comply with the requirements of auditing standards. An example is a firm assigning unqualified assistants to perform certain audit tasks where they failed to notice material misstatements in the client’s records that a qualified auditor would have found.  Audit risk  represents the possibility that the auditor concludes after conducting an adequate audit that the financial statements were fairly stated when, in fact, they were materially misstated. Audit risk is unavoidable, because auditors gather evidence only on a test basis and because well-concealed frauds are extremely difficult to detect. An auditor may fully comply with auditing standards and still fail to uncover a material misstatement due to fraud.

Accounting professionals tend to agree that in most cases, when an audit has failed to uncover material misstatements and the wrong type of audit opinion is issued, it is appropriate to question whether the auditor exercised due care in performing the audit. In cases of audit failure, the law often allows parties who suffered losses to recover some or all of the losses caused by the audit failure. In practice, because of the complexity of auditing, it is difficult to determine when the auditor has failed to use due care. Also, legal precedent makes it difficult to determine who has the right to expect the benefit of an audit and recover losses in the event of an audit failure. Nevertheless, an auditor’s failure to follow due care often results in liability and, when appropriate, damages against the CPA firm.

As highlighted by the lawsuit against Orange & Rankle in the opening story, difficulties often arise when a business failure, not an audit failure, occurs. For example, when a company files for bankruptcy protection or cannot pay its debts, statement users commonly claim that an audit failure has occurred, especially when the most recently issued auditor’s report indicates that the financial statements were fairly stated. Even worse, if a business failure happens and the financial statements are later determined to have been misstated, users may claim the auditor was negligent even if the audit was conducted in accordance with auditing standards. This conflict between statement users and auditors often arises because of an “expectation gap” between users and auditors. Most auditors believe that the conduct of the audit in accordance with auditing standards is all that can be expected of auditors. However, many users believe that auditors guarantee the accuracy of financial statements, and some users even believe that the auditor guarantees the financial viability of the business. Fortunately for the profession, courts continue to support the auditor’s view. Nonetheless, the expectation gap often results in unwarranted lawsuits. The profession must continue to educate statement users about the role of auditors and the differences between business failure, audit failure, and audit risk. However, auditors must recognize that, in part, the claims of audit failure result from the hope of those who suffer a business loss to recover from any source, regardless of who is at fault.

LEGAL CONCEPTS AFFECTING LIABILITY

OBJECTIVE 5-3

Use the primary legal concepts and terms concerning accountants’ liability as a basis for studying legal liability of auditors.

A CPA is responsible for every aspect of his or her public accounting work, including auditing, taxes, management advisory services, and accounting and bookkeeping services. If a CPA failed to correctly prepare and file a client’s tax return, the CPA can be held liable for any penalties and interest that the client was required to pay plus the tax preparation fee charged. In some states, the court can also assess punitive damages.

Most of the major lawsuits against CPA firms have dealt with audited or unaudited financial statements. The discussion in this chapter is restricted primarily to those two aspects of public accounting. First, we examine several legal concepts pertinent to lawsuits involving CPAs.

Prudent Person Concept

There is agreement within the profession and the courts that the auditor is not a guarantor or insurer of financial statements. The auditor is expected only to conduct the audit with due care, and is not expected to be perfect. This standard of due care is often called the  prudent person concept . It is expressed in Cooley on Torts as follows:

· • Every man who offers his service to another and is employed assumes the duty to exercise in the employment such skill as he possesses with reasonable care and diligence. In all these employments where peculiar skill is prerequisite, if one offers his service, he is understood as holding himself out to the public as possessing the degree of skill commonly possessed by others in the same employment, and, if his pretensions are unfounded, he commits a species of fraud upon every man who employs him in reliance on his public profession. But no man, whether skilled or unskilled, undertakes that the task he assumes shall be performed successfully, and without fault or error. He undertakes for good faith and integrity, but not for infallibility, and he is liable to his employer for negligence, bad faith, or dishonesty, but not for losses consequent upon pure errors of judgment.

Liability for the Acts of Others

Generally, the partners, or shareholders in the case of a professional corporation, are jointly liable for the civil actions against any owner. It is different, however, if the firm operates as a limited liability partnership (LLP), a limited liability company (LLC), a general corporation, or a professional corporation with limited liability. Under these business structures, the liability for one owner’s actions does not extend to another owner’s personal assets, unless the other owner was directly involved in the actions of the owner causing the liability. Of course, the firm’s assets are all subject to the damages that arise.

The partners may also be liable for the work of others on whom they rely under the laws of agency. The three groups an auditor is most likely to rely on are employees, other CPA firms engaged to do part of the work, and specialists called upon to provide technical information. If an employee performs improperly in doing an audit, the partners can be held liable for the employee’s performance.

Lack of Privileged Communication

Under common law, CPAs do not have the right to withhold information from the courts on the grounds that the information is privileged. Confidential discussions between the client and auditor cannot be withheld from the courts. (See  page 97  in  Chapter 4  on how auditor’s documentation can be subpoenaed by a court.)

Several states have statutes that permit privileged communication between the client and auditor. Even then, the intent at the time of the communication must have been for the communication to remain confidential. A CPA can refuse to testify in a state with privileged communications statutes. However, that privilege does not extend to federal courts.

Legal Terms Affecting CPAs’ Liability

Before proceeding in the discussion of legal liability, we examine several common legal terms that affect CPAs’ liability. These terms are defined in  Table 5-1 . Take a moment to review these definitions. When the auditor has failed to conduct an adequate audit, liability may depend on the level of negligence, which can range from ordinary negligence to fraud. Also note the distinction between joint and several liability and separate and proportionate liability, because the amounts assessed will likely vary greatly between these two approaches when courts assess damages. Generally, these damage approaches only apply in cases of liability to third parties under common law and under the federal securities laws. When lawsuits are filed in state court, state laws determine which approach to damages applies. When lawsuits are brought under the federal securities laws, the separate and proportionate approach applies, except where it can be shown that the CPA defendant had actual knowledge of fraud or has participated in fraud, in which case joint and several liability applies. Under the federal statutes, the amount of damages under separate and proportionate liability can be increased to 150 percent of the amount determined to be proportionate to the CPA’s degree of fault when the main defendant is insolvent.

TABLE 5-1 Legal Terms Affecting CPAs’ Liability

Legal Term

Description

Terms Related to Negligence and Fraud

Ordinary negligence

Absence of reasonable care that can be expected of a person in a set of circumstances. For auditors, it is in terms of what other competent auditors would have done in the same situation.

Gross negligence

Lack of even slight care, tantamount to reckless behavior, that can be expected of a person. Some states do not distinguish between ordinary and gross negligence.

Constructive fraud

Existence of extreme or unusual negligence even though there was no intent to deceive or do harm. Constructive fraud is also termed recklessness. Recklessness in the case of an audit is present if the auditor knew an adequate audit was not done but still issued an opinion, even though there was no intention of deceiving statement users.

Fraud

Occurs when a misstatement is made and there is both the knowledge of its falsity and the intent to deceive.

Terms Related to Contract Law

Breach of contract

Failure of one or both parties in a contract to fulfill the requirements of the contract. An example is the failure of a CPA firm to deliver a tax return on the agreed-upon date. Parties who have a relationship that is established by a contract are said to have privity of contract.

Third-party beneficiary

A third party who does not have privity of contract but is known to the contracting parties and is intended to have certain rights and benefits under the contract. A common example is a bank that has a large loan outstanding at the balance sheet date and requires an audit as a part of its loan agreement.

Other Terms

Common law

Laws that have been developed through court decisions rather than through government statutes.

Statutory law

Laws that have been passed by the U.S. Congress and other governmental units. The Securities Acts of 1933 and 1934 and Sarbanes–Oxley Act of 2002 are important statutory laws affecting auditors.

Joint and several liability

The assessment against a defendant of the full loss suffered by a plaintiff, regardless of the extent to which other parties shared in the wrongdoing. For example, if management intentionally misstates financial statements, an auditor can be assessed the entire loss to shareholders if the company is bankrupt and management is unable to pay.

Separate and proportionate liability

The assessment against a defendant of that portion of the damage caused by the defendant’s negligence. For example, if the courts determine that an auditor’s negligence in conducting an audit was the cause of 30% of a loss to a defendant, only 30% of the aggregate damage will be assessed to the CPA firm.

Sources of Legal Liability

The remainder of this chapter addresses the four sources of auditor’s  legal liability :

· 1. Liability to clients

· 2. Liability to third parties under common law

· 3. Civil liability under the federal securities laws

· 4. Criminal liability

Figure 5-1  provides examples of each of these classifications of liability. Let’s examine each of these liability classifications in more detail.

LIABILITY TO CLIENTS

OBJECTIVE 5-4

Describe accountants’ liability to clients and related defenses.

The most common source of lawsuits against CPAs is from clients. The suits vary widely, including such claims as failure to complete a nonaudit engagement on the agreed-upon date, inappropriate withdrawal from an audit, failure to discover an embezzlement (theft of assets), and breach of the confidentiality requirements of CPAs. Typically, the amount of these lawsuits is relatively small, and they do not receive the publicity often given to suits involving third parties.

A typical lawsuit brought by a client involves a claim that the auditor did not discover an employee theft as a result of negligence in the conduct of the audit. The lawsuit can be for breach of contract, a tort action for negligence, or both. Tort actions are more common because the amounts recoverable under them are normally larger than under breach of contract. Tort actions can be based on ordinary negligence, gross negligence, or fraud. Refer to  Table 5-1  for distinctions among these three levels of negligent actions.

FIGURE 5-1 Four Major Sources of Auditors’ Legal Liability

The principal issue in cases involving alleged negligence is usually the level of care required. Although it is generally agreed that no one is perfect, not even a professional, in most instances, any significant error or mistake in judgment creates at least a presumption of negligence that the professional will have to rebut. In audits, failure to meet auditing standards is often conclusive evidence of negligence. Let’s examine a typical case that raised the question of negligent performance by a CPA firm: Cenco Incorporated v. Seidman & Seidman. The case, which is described in more detail in  Figure 5-2 , involved alleged negligence by the auditor in failing to find fraud. In the legal suit by Cenco’s management, the auditor was able to successfully argue that it was not negligent and that the previous management team’s deceitful actions had prevented the auditor from uncovering the fraud.

FIGURE 5-2 Cenco Incorporated v. Seidman & Seidman (1982)—Liability to Clients

The question of level of care becomes more difficult in the environment of a review or a compilation of financial statements in which there are fewer accepted standards to evaluate performance.  Figure 5-3  ( p. 120 ) summarizes a widely known example of a lawsuit dealing with the failure to uncover fraud in unaudited financial statements. Although the CPA was never engaged to conduct an audit for the 1136 Tenants Corporation, the CPA was found liable for failing to detect an embezzlement scheme conducted by one of the client’s managers. One of the reasons for this outcome was the lack of a clear understanding between the client and the CPA as to the exact nature of the services to be performed by the CPA. As noted in  Figure 5-3 engagement letters between the client and the CPA firm developed as a result of this case. Now, CPA firms and clients typically sign engagement letters, which are required for audits, to formalize their agreements about the services to be provided, fees, and timing. Privity of contract (see breach of contract in Table 5-1 ) can exist without a written agreement, but an engagement letter defines the contract more clearly.

FIGURE 5-3 1136 Tenants v. Max Rothenberg and Company (1967)—Liability to Clients

Auditor’s Defenses Against Client Suits

The CPA firm normally uses one or a combination of four defenses when there are legal claims by clients: lack of duty to perform the service, nonnegligent performance, contributory negligence, and absence of causal connection.

Lack of Duty

The  lack of duty to perform  the service means that the CPA firm claims that there was no implied or expressed contract. For example, the CPA firm might claim that misstatements were not uncovered because the firm did a review service, not an audit. The CPA’s use of an engagement letter provides a basis to demonstrate a lack of duty to perform. Many litigation experts believe that a well-written engagement letter significantly reduces the likelihood of adverse legal actions.

Nonnegligent Performance

For nonnegligent performance in an audit, the CPA firm claims that the audit was performed in accordance with auditing standards. Even if there were undiscovered misstatements, the auditor is not responsible if the audit was conducted properly. The prudent person concept (discussed on page 116 ) establishes in law that the CPA firm is not expected to be infallible. Similarly, auditing standards make it clear that an audit is subject to limitations and cannot be relied on for complete assurance that all misstatements will be found. Requiring auditors to discover all material misstatements would, in essence, make them insurers or guarantors of the accuracy of the financial statements. The courts do not require that.

Contributory Negligence

A defense of  contributory negligence  exists when the auditor claims the client’s own actions either resulted in the loss that is the basis for damages or interfered with the conduct of the audit in such a way that prevented the auditor from discovering the cause of the loss. Suppose a client claims that a CPA firm was negligent in not uncovering an employee’s theft of cash. If the CPA firm had notified the client (preferably in writing) of a deficiency in internal control that would have prevented the theft but management did not correct it, the CPA firm would have a defense of contributory negligence. Or, suppose a CPA firm failed to determine that certain accounts receivable were uncollectible and, in reviewing collectibility, the auditors were lied to and given false documents by the credit manager. In this circumstance, assuming the audit of accounts receivable was done in accordance with auditing standards, the auditor can claim a defense of contributory negligence.

Absence of Causal Connection

To succeed in an action against the auditor, the client must be able to show that there is a close causal connection between the auditor’s failure to follow auditing standards and the damages suffered by the client. Assume that an auditor failed to complete an audit on the agreed-upon date. The client alleges that this caused a bank not to renew an outstanding loan, which caused damages. A potential auditor defense is that the bank refused to renew the loan for other reasons, such as the weakening financial condition of the client. This defense is called an  absence of causal connection .

LIABILITY TO THIRD PARTIES UNDER COMMON LAW

OBJECTIVE 5-5

Describe accountants’ liability to third parties under common law and related defenses.

In addition to being sued by clients, CPAs may be liable to third parties under common law. Third parties include actual and potential stockholders, vendors, bankers and other creditors, employees, and customers. A CPA firm may be liable to third parties if a loss was incurred by the claimant due to reliance on misleading financial statements. A typical suit occurs when a bank is unable to collect a major loan from an insolvent customer and the bank then claims that misleading audited financial statements were relied on in making the loan and that the CPA firm should be held responsible because it failed to perform the audit with due care.

Ultramares Doctrine

The leading precedent-setting auditing case in third-party liability was Ultramares Corporation v.Touche (1931), which established the  Ultramares   doctrine . Take a moment to read the summary of the case in  Figure 5-4 .

In this case, the court held that although the accountants were negligent, they were not liable to the creditors because the creditors were not a primary beneficiary. In this context, a primary beneficiary is one about whom the auditor was informed before conducting the audit (a known third party). This case established a precedent, commonly called the Ultramares doctrine, that ordinary negligence is insufficient for liability to third parties because of the lack of privity of contract between the third party and the auditor, unless the third party is a primary beneficiary. However, in a subsequent trial of the Ultramares case, the court pointed out that had there been fraud or gross negligence on the part of the auditor, the auditor could be held liable to third parties who are not primary beneficiaries.

FIGURE 5-4 Ultramares Corporation v. Touche (1931)—Liability to Third Parties

Foreseen Users

In recent years, courts have broadened the Ultramares doctrine to allow recovery by third parties in more circumstances by introducing the concept of  foreseen users , who are members of a limited class of users that the auditor knows will rely on the financial statements. For example, a bank that has loans outstanding to a client at the balance sheet date may be a foreseen user. Under this concept, a foreseen user is treated the same as a known third party.

Although the concept of foreseen users may appear straightforward, courts have generated several different interpretations. At present, the three leading approaches taken by the courts that have emerged are described as follows:

Credit Alliance

In Credit Alliance v. Arthur Andersen & Co. (1986) in New York, a lender brought suit against the auditor of one of its borrowers, claiming that it relied on the financial statements of the borrower, who was in default, in granting the loan. The New York State Court of Appeals upheld the basic concept of privity established by Ultramares and stated that to be liable (1) an auditor must know and intend that the work product would be used by the third party for a specific purpose, and (2) the knowledge and intent must be evidenced by the auditor’s conduct.

Restatement of Torts

The approach followed by most states is to apply the rule cited in the Restatement of Torts, an authoritative set of legal principles. The Restatement Rule is that foreseen users must be members of a reasonably limited and identifiable group of users that have relied on the CPA’s work, such as creditors, even though those persons were not specifically known to the CPA at the time the work was done. A leading case supporting the application of this rule is Rusch Factors v. Levin, as presented in  Figure 5-5 .

Foreseeable User

The broadest interpretation of the rights of third-party beneficiaries is to use the concept of foreseeable users . Under this concept, any users that the auditor should have reasonably been able to foresee as likely users of the client’s financial statements have the same rights as those with privity of contract. These users are often called an unlimited class. Although a significant number of states followed this approach in the past, it is now used in only two states.

Table 5-2  summarizes the three approaches to third party liability taken by the courts under common law. There is confusion caused by these differing views of liability to third parties under common law, but the movement is clearly away from the foreseeable user approach, and thus toward the first two approaches. For example, in Bily v. Arthur Young (1992), the California Supreme Court reversed a lower court decision against Arthur Young, clearly upholding theRestatement doctrine. In its decision, the court stated that “an auditor owes no general duty of care regarding the conduct of an audit to persons other than the client” and reasoned that the potential liability to auditors under the foreseeable user doctrine would be distinctly out of proportion to any fault.

FIGURE 5-5 Rusch Factors v. Levin (1968)—Liability to Third Parties

TABLE 5-2 Approaches Courts Take to Assign Third Party Liability Under Common Law

Auditor Defenses Against Third-Party Suits

Three of the four defenses available to auditors in suits by clients are also available in third-party lawsuits: lack of duty to perform the service, nonnegligent performance, and absence of causal connection. Contributory negligence is ordinarily not available because a third party is not in a position to contribute to misstated financial statements.

A lack of duty defense in third-party suits contends lack of privity of contract. The extent to which privity of contract is an appropriate defense and the nature of the defense depend heavily on the approach to foreseen users in the state and the judicial jurisdiction of the case.

If the auditor is unsuccessful in using the lack of duty defense to have a case dismissed, the preferred defense in third-party suits is nonnegligent performance. If the auditor conducted the audit in accordance with auditing standards, that eliminates the need for the other defenses. Unfortunately, nonnegligent performance can be difficult to demonstrate to a court, especially in jury trials when laypeople with no accounting experience make up the jury.

Absence of causal connection in third-party suits often means nonreliance on the financial statements by the user. Assume that the auditor can demonstrate that a lender relied on an ongoing banking relationship with a customer, rather than the financial statements, in making a loan. In that situation, auditor negligence in the conduct of the audit is not relevant. Of course, it is difficult to prove nonreliance on the financial statements. Absence of causal connection can be difficult to establish because users may claim reliance on the statements even when investment or loan decisions were made without considering the company’s financial condition.

CIVIL LIABILITY UNDER THE FEDERAL SECURITIES LAWS

OBJECTIVE 5-6

Describe accountants’ civil liability under the federal securities laws and related defenses.

Although there has been some growth in actions brought against accountants by clients and third parties under common law, the greatest growth in CPA liability litigation has been under the federal securities laws. Litigants commonly seek federal remedies because of the availability of class-action litigation and the ability to obtain significant damages from defendants.

Other factors also make federal courts attractive to litigants. For example, several sections of the securities laws impose strict liability standards on CPAs and federal courts are often likely to favor plaintiffs in lawsuits when there are strict standards. However, fairly recent tort reform legislation may result in a reduction of negative outcomes for CPA firms in federal courts.

Securities Act of 1933

The  Securities Act of 1933  deals only with the reporting requirements for companies issuing new securities, including the information in registration statements and prospectuses. The only parties who can recover from auditors under the 1933 act are the original purchasers of securities. The amount of the potential recovery equals the original purchase price less the value of the securities at the time of the suit. (If the securities have been sold, users can recover the amount of the loss incurred.)

The Securities Act of 1933 imposes an unusual burden on the auditor. Section 11 of the 1933 act defines the rights of third parties and auditors, which are summarized as follows:

· • Any third party who purchased securities described in the registration statement may sue the auditor for material misrepresentations or omissions in audited financial statements included in the registration statement.

· • Third-party users do not have the burden of proof that they relied on the financial statements or that the auditor was negligent or fraudulent in doing the audit. Users must only prove that the audited financial statements contained a material misrepresentation or omission.

· • The auditor has the burden of demonstrating as a defense that (1) an adequate audit was conducted or (2) all or a portion of the plaintiff’s loss was caused by factors other than the misleading financial statements. The 1933 act is the only common or statutory law where the burden of proof is on the defendant.

Furthermore, the auditor is responsible for making sure that the financial statements are fairly stated beyond the date of issuance, up to the date the registration statement becomes effective, which can be several months later. Assume that the audit report date for December 31, 2010 financial statements is February 10, 2011, but the registration statement is dated November 1, 2011. In a typical audit, the auditor must review transactions through the audit report date, February 10, 2011. In statements filed under the 1933 act, the auditor is responsible for reviewing transactions – for almost nine additional months – through the registration statement date, November 1, 2011.

FIGURE 5-6 Escott et al. v. BarChris Construction Corporation (1968)—Securities Act of 1933

Although the burden may appear harsh to auditors, there have been relatively few cases tried under the 1933 act. One of the most significant is Escott et al. v. BarChris Construction Corporation(1968). As noted in  Figure 5-6 , the CPA firm was held liable for a lack of due diligence required under the 1933 act when performing its review of events occurring subsequent to the balance sheet date. This case brought about two noteworthy consequences:

· 1. Auditing standards were changed to require greater emphasis on procedures that the auditor must perform for events subsequent to the balance sheet date.

· 2. A greater emphasis began to be placed on the importance of the audit staff understanding the client’s business and industry.

Securities Exchange Act of 1934

The liability of auditors under the  Securities Exchange Act of 1934  often centers on the audited financial statements issued to the public in annual reports submitted to the SEC as a part of annual Form 10-K reports. Every company with securities traded on national and over-the-counter exchanges is required to submit audited statements annually. Obviously, a much larger number of statements fall under the 1934 act than under the 1933 act.

Auditors also face potential legal exposure for quarterly information (Form 10-Q) or other reporting information filed with the SEC, such as an unusual event filed in a Form 8-K. The auditor must perform a review of the Form 10-Q before it is filed with the SEC, and the auditor is frequently involved in reviewing the information in other reports, and, therefore, may be legally responsible. However, few cases have involved auditors for reports other than reports on annual audits.

FIGURE 5-7 Hochfelder v. Ernst & Ernst (1976)—Securities Exchange Act of 1934

Rule 10b-5 of the Securities Exchange Act of 1934

The principal focus on CPA liability litigation under the 1934 act is Rule 10b-5. Section 10 and Rule 10b-5 are often called the antifraud provisions of the 1934 act, as they prohibit any fraudulent activities involving the purchase or sale of any security. Numerous federal court decisions have clarified that Rule 10b-5 applies not only to direct sellers but also to accountants, underwriters, and others. Generally, accountants can be held liable under Section 10 and Rule 10b-5 if they intentionally or recklessly misrepresent information intended for third-party use.

In 1976, in Hochfelder v. Ernst & Ernst, known both as a leading securities law case and as a CPA liabilities case, the U.S. Supreme Court ruled that scienter, which is knowledge and intent to deceive, is required before CPAs can be held liable for violation of Rule 10b-5. A summary ofHochfelder is included in  Figure 5-7  ( p. 125 ).

Many auditors believed the knowledge and intent to deceive requirement established in theHochfelder case would significantly reduce auditors’ exposure to liability. However, subsequent cases were brought arguing the knowledge and deceit standard was met in cases in which the auditor knew all the relevant facts but made poor judgments. In such situations, the courts emphasized that the CPAs had requisite knowledge. The Solitron Devices case, described in  Figure 5-8 , is an example of that reasoning. In that case, the court of appeals ruled that reckless behavior on the part of the auditor was sufficient to hold the auditor liable for violation of Rule 10b-5. However, in subsequent suits under Rule 10b-5, Worlds of Wonder (1994) and Software Toolworks(1994), two key Ninth Circuit court decisions stated that poor judgment isn’t proof of fraud. This view appears now to be winning favor in the courts. Although Rule 10b-5 continues to be a basis for lawsuits against auditors, Hochfelder and subsequent court decisions have limited the liability somewhat.

Auditor Defenses–1934 Act

The same three defenses available to auditors in common-law suits by third parties are also available for suits under the 1934 act: nonnegligent performance, lack of duty, and absence of causal connection.

As we just discussed, the use of the lack of duty defense in response to actions under Rule 10b-5 has had varying degrees of success, depending on the jurisdiction. In the Hochfelder case, the court ruled that knowledge and intent to deceive were necessary for the auditor to be found liable. In other cases, negligent or reckless behavior was sufficient for the auditor to be found liable. Continued court interpretations are likely to clarify this unresolved issue.

SEC Sanctions

FIGURE 5-8 Howard Sirota v. Solitron Devices, Inc. (1982)–Securities Exchange Act of 1934

Closely related to auditors’ liability is the SEC’s authority to sanction. The SEC has the power in certain circumstances to sanction or suspend practitioners from doing audits for SEC companies. The SEC’s Rules of Practice permit them to temporarily or permanently deny a CPA or CPA firm from being associated with financial statements of public companies, either because of a lack of appropriate qualifications or having engaged in unethical or improper professional conduct.

In recent years, the SEC has temporarily suspended a number of individual CPAs from doing any audits of SEC clients. It has similarly prohibited a number of CPA firms from accepting any new SEC clients for a period, such as six months. In some cases, the SEC has required an extensive review of a major CPA firm’s practices by another CPA firm, or made CPA firms make changes in their practices. Individual CPAs and their firms have also been required to participate in continuing education programs. Sanctions such as these are published by the SEC and are often reported in the business press, making them a significant embarrassment to those involved.

Foreign Corrupt Practices Act of 1977

Another significant congressional action affecting both CPA firms and their clients was the passage of the  Foreign Corrupt Practices Act of 1977 . The act makes it illegal to offer a bribe to an official of a foreign country for the purpose of exerting influence and obtaining or retaining business. The prohibition against payments to foreign officials is applicable to all U.S. domestic firms, regardless of whether they are publicly or privately held, and to all foreign companies filing with the SEC.

The law also requires SEC registrants under the Securities Exchange Act of 1934 to meet additional requirements of reasonably complete and accurate records, plus an adequate system of internal control. The law significantly affected all SEC companies, and potentially affected auditors because of their responsibility to review and evaluate systems of internal control as a part of the audit. Although the provisions of the Foreign Corrupt Practices Act remain in effect, the provisions related to accounting records and internal control are largely superseded by the more stringent requirements of the Sarbanes–Oxley Act of 2002.

Sarbanes–Oxley Act of 2002

The Sarbanes–Oxley Act greatly increases the responsibilities of public companies and their auditors. The Act requires the CEO and CFO to certify the annual and quarterly financial statements filed with the SEC. In addition, as discussed in  Chapter 3  ( p. 49 51 ), management must report its assessment of the effectiveness of internal control over financial reporting, and for accelerated filers, the auditor must provide an opinion on the effectiveness of internal control over financial reporting. As a result, auditors may be exposed to legal liability related to their opinions on internal control. The PCAOB also has the authority to sanction registered CPA firms for any violations of the Act.

Table 5-3  ( p. 128 ) summarizes the sources of liability to clients and others for breach of contract under common law, liability to third parties under common law, and liability to third parties under the 1933 and 1934 Securities acts. The table illustrates the strict burden on auditors to defend themselves under the 1933 act. Liability to third parties under common law and the 1934 act depends on the degree of negligence. Liability to third parties under common law also depends upon the jurisdiction and whether the third party is a primary beneficiary or known user of the financial statements.

The defenses available to the auditor are summarized in  Table 5-4  ( p. 128 ). If the auditor is unable to prove a lack of duty to perform the service, the preferred defense is generally nonnegligent performance.

CRIMINAL LIABILITY

OBJECTIVE 5-7

Specify what constitutes criminal liability for accountants.

A fourth way CPAs can be held liable is under  criminal liability for accountants . CPAs can be found guilty for criminal action under both federal and state laws. Under state law, the most likely statutes to be enforced are the Uniform Securities Acts, which are similar to parts of the SEC rules. The more relevant federal laws affecting auditors are the 1933 and 1934 securities acts, as well as the Federal Mail Fraud Statute and the Federal False Statements Statute. All make it a criminal offense to defraud another person through knowingly being involved with false financial statements. In addition, the Sarbanes–Oxley Act of 2002 made it a felony to destroy or create documents to impede or obstruct a federal investigation. Under Sarbanes–Oxley, a person may face fines and imprisonment of up to 20 years for altering or destroying documents. These provisions were adopted following the United States v. Andersen (2002) case described in  Figure 5-9 , in which the government charged Andersen with obstruction of justice for the destruction and alteration of documents related to its audit of Enron.

TABLE 5-3 Summary of Auditor Liability

Alleged Auditor Action

Liability to Client

Third Parties under Common Law

Liability to Third Partiesunder 1933 Securities Act

Liability to Third Partiesunder 1934 Securities Act

Breach of contract

Yes

N/A

N/A

N/A

Negligence

Yes

Primary Beneficiary—Yes

N/A 1

No

 

 

Other third parties—depends on jurisdiction

 

 

Gross Negligence

Yes

Yes

N/A

Yes—likely

Constructive fraud/Recklessness

Yes

Yes

N/A

Yes—likely

Fraud

Yes

Yes

N/A

Yes—likely

“Yes” indicates that the auditor could be held liable to a client or third party for the alleged audit or action.

“No” means the auditor would not be liable for the alleged action.

“N/A” means that the alleged auditor action is not an available basis to seek liability from the auditor under common law or the securities acts.

1

Material error or omission is required for liability under the 1933 act.

Unfortunately, a few notorious criminal cases have involved CPAs. Historically, one of the leading cases of criminal action against CPAs is United States v. Simon, which occurred in 1969. In this case, three auditors were prosecuted for filing false financial statements of a client with the government, and all three were held criminally liable. Three major criminal cases followed Simon:

TABLE 5-4 Auditor Defenses Against Suits by Client, Third Parties Under Common Law, and Under the 1933 and 1934 Securities Acts

Available Auditor Defenses

Client Suits

Third Parties Common Law

1933 Securities Act

1934 Securities Act

Lack of duty to perform service

X

X

N/A

X

Nonnegligent performance (audit in accordance with audit standards)

X

X

X1

X

Contributory negligence by client or third party

X

N/A

N/A

N/A

Absence of causal connection (no reliance on financial statements)

X

X

N/A 2

X

“X” indicates the auditor defense would be available.

“N/A” indicates the defense generally would not be applicable.

1

Under the 1933 Securities Act, the auditor must prove due diligence in the performance of the audit.

2

Auditor may prove that the loss was not attributable to the misleading financial statements.

FIGURE 5-9 United States v. Andersen (2002)—Criminal Liability

· • In United States v. Natelli (1975), two auditors were convicted of criminal liability under the 1934 act for certifying financial statements of National Student Marketing Corporation that contained inadequate disclosures.

· • In United States v. Weiner (1975), three auditors were convicted of securities fraud in connection with their audit of Equity Funding Corporation of America. The fraud was so extensive and the audit work so poor that the court concluded that the auditors must have been aware of the fraud and were therefore guilty of knowing complicity.

· • In ESM Government Securities v. Alexander Grant & Co. (1986), management revealed to the partner in charge of the audit of ESM that the previous year’s audited financial statements contained a material misstatement. Rather than complying with professional and firm standards, the partner agreed to say nothing in the hope that management would work its way out of the problem during the current year. The partner was convicted of criminal charges for his role in sustaining the fraud.

LESSONS LEARNED FROM AUDITOR LITIGATION

As we consider the advisability of legislation for the reform of accountants’ liability, it is useful to review actual experiences with past accountants’ litigation. Accordingly, a review was conducted of 23 cases of alleged audit failure with which I have been involved as a litigation consultant and expert witness. Of these 23 cases, six were clearly without merit and should not have been brought on equitable grounds. Of the 17 that were with merit, 13 did, in fact, represent a real audit failure. Considering the nature of the failure in each case, the evidence that would lead the auditor to identify the misstatement was usually present. In other words, the problem was not any inadequacy in the audit process as presented by professional standards; it was a lack of professional skepticism on the part of the auditor. The auditor had evidence in his or her possession that indicated the problem, but did not see it as such.

Source: Presentation by James K. Loebbecke at the Forum on Responsibilities and Liabilities of Accountants and Auditors, United Nations Conference on Trade and Development, March 16, 1995.

These cases teach several critical lessons:

· • An investigation of the integrity of management is an important part of deciding on the acceptability of clients and the extent of work to perform. Auditing guidance for auditors in investigating new clients will be discussed in  Chapter 8 .

· • As discussed in  Chapter 4 , independence by all individuals on the engagement is essential, especially in a defense involving criminal actions.

· • Transactions with related parties require special scrutiny because of the potential for misstatement. Auditing requirements for related-party transactions are discussed in Chapter 8 .

· • Accounting principles cannot be relied on exclusively in deciding whether financial statements are fairly presented. The substance of the statements, considering all facts, is required.

· • The potential consequences of the auditor knowingly committing a wrongful act are so severe that it is unlikely that the potential benefits can ever justify the actions.

THE PROFESSION’S RESPONSE TO LEGAL LIABILITY

OBJECTIVE 5-8

Describe how the profession and individual CPAs can reduce the threat of litigation.

The AICPA and the profession as a whole can do a number of things to reduce practitioners’ exposure to lawsuits:

· 1. Seek protection from nonmeritorious litigation

· 2. Improve auditing to better meet users’ needs

· 3. Educate users about the limits of auditing

Let’s discuss some specific activities briefly:

· • Standard and rule setting. The IAASB, AICPA and PCAOB must constantly set standards and revise them to meet the changing needs of auditing. For example, changes in auditing standards on the auditor’s responsibility to detect fraud were issued to address users’ needs and expectations as to auditor performance.

· • Oppose lawsuits. CPA firms must continue to oppose unwarranted lawsuits even if, in the short run, the costs of winning are greater than the costs of settling.

· • Education of users. The AICPA, leaders of CPA firms, and educators should educate investors and others who read financial statements as to the meaning of an auditor’s opinion and to the extent and nature of the auditor’s work. In addition, users need to understand that auditors do not guarantee the accuracy of the financial records or the future prosperity of an audited company. People outside of the profession need to understand that accounting and auditing are arts, not sciences. Perfection and precision are simply not achievable.

· • Sanction members for improper conduct and performance. A profession must police its own membership. The AICPA and the PCAOB have made progress in dealing with the problems of inadequate CPA performance, but more rigorous review of alleged failures is still needed.

· • Lobby for changes in laws. Since the 1990s several changes in state and federal laws have favorably impacted the legal environment for the profession. Most states have revised their laws to allow accounting firms to practice in different organizational forms, including limited liability organizations that provide some protection from litigation. The passage of the  Private Securities Litigation Reform Act of 1995  (the Reform Act) and the Securities Litigation Uniform Standards Act of 1998 significantly reduced potential damages in federal securities-related litigation by providing for proportionate liability in most instances. The profession continues to pursue litigation reform at the state level, including application of a strict privity standard for liability to nonclients and proportionate liability in all cases not involving fraud.

PROTECTING INDIVIDUAL CPAs FROM LEGAL LIABILITY

Practicing auditors may also take specific action to minimize their liability. Some of the more common actions are as follows:

· • Deal only with clients possessing integrity. There is an increased likelihood of having legal problems when a client lacks integrity in dealing with customers, employees, units of government, and others. A CPA firm needs procedures to evaluate the integrity of clients and should dissociate itself from clients found lacking integrity.

· • Maintain independence. Independence is more than merely financial. Independence requires an attitude of responsibility separate from the client’s interest. Much litigation has arisen from auditors’ too-willing acceptance of client representations or from client pressure. The auditor must maintain an attitude of healthy professional skepticism.

· • Understand the client’s business. In several cases, the lack of knowledge of industry practices and client operations has been a major factor in auditors failing to uncover misstatements.

· • Perform quality audits. Quality audits require that auditors obtain appropriate evidence and make appropriate judgments about the evidence. It is essential, for example, that the auditor understands the client’s internal controls and modify the evidence to reflect the findings. Improved auditing reduces the likelihood of failing to detect misstatements and the likelihood of lawsuits.

· • Document the work properly. The preparation of good audit documentation helps the auditor perform quality audits. Quality audit documentation is essential if an auditor has to defend an audit in court, including an engagement letter and a representation letterthat define the respective obligations of the client and the auditor.

· • Exercise professional skepticism. Auditors are often liable when they are presented with information indicating a problem that they fail to recognize. Auditors need to strive to maintain a healthy level of skepticism, one that keeps them alert to potential misstatements, so that they can recognize misstatements when they exist.

It is also important for CPAs to carry adequate insurance and choose a form of organization that provides some form of legal liability protection to owners. In the event of actual or threatened litigation, an auditor should consult with experienced legal counsel.

SUMMARY

This chapter provides insight into the environment in which CPAs operate by highlighting the significance of the legal liability facing the CPA profession. No reasonable CPA wants to eliminate the profession’s legal responsibility for fraudulent or incompetent performance. It is certainly in the profession’s best interest to maintain public trust in the competent performance of the auditing profession, while avoiding liability for cases involving strictly business failure and not audit failure. To more effectively avoid legal liability, CPAs need to have an understanding of how they can be held liable to their clients or third parties. Knowledge about how CPAs are liable to clients under common law, to third parties under common law, to third parties under federal securities laws, and for criminal liability, provides auditors an awareness of issues that may subject them to greater liability. CPAs can protect themselves from legal liability in numerous ways, and the profession has worked diligently to identify ways to help CPAs reduce the profession’s potential exposure. It is necessary for the profession and society to determine a reasonable trade-off between the degree of responsibility the auditor should take for the financial statements and the audit cost to society. CPAs, Congress, the SEC, and the courts will all continue to have a major influence in shaping the final solution.

ESSENTIAL TERMS

Absence of causal connection

—an auditor’s legal defense under which the auditor contends that the damages claimed by the client were not brought about by any act of the auditor

Audit failure

—a situation in which the auditor issues an incorrect audit opinion as the result of an underlying failure to comply with the requirements of auditing standards

Audit risk

—the risk that the auditor will conclude after conducting an adequate audit that the financial statements are fairly stated and an unqualified opinion can therefore be issued when, in fact, they are materially misstated

Business failure

—the situation when a business is unable to repay its lenders or meet the expectations of its investors because of economic or business conditions

Contributory negligence

—an auditor’s legal defense under which the auditor claims that the client failed to perform certain obligations and that it is the client’s failure to perform those obligations that brought about the claimed damages

Criminal liability for accountants

—defrauding a person through knowing involvement with false financial statements

Foreign Corrupt Practices Act of 1977

—a federal statute that makes it illegal to offer a bribe to an official of a foreign country for the purpose of exerting influence and obtaining or retaining business and that requires U.S. companies to maintain reasonably complete and accurate records and an adequate system of internal control

Foreseeable users

—an unlimited class of users that the auditor should have reasonably been able to foresee as being likely users of financial statements

Foreseen users

—members of a limited class of users whom the auditor is aware will rely on the financial statements

Lack of duty to perform

—an auditor’s legal defense under which the auditor claims that no contract existed with the client; therefore, no duty existed to perform the disputed service

Legal liability

—the professional’s obligation under the law to provide a reasonable level of care while performing work for those served

Nonnegligent performance

—an auditor’s legal defense under which the auditor claims that the audit was performed in accordance with auditing standards

Private Securities Litigation Reform Act of 1995

—a federal law passed in 1995 that significantly reduced potential damages in securities-related litigation

Prudent person concept

—the legal concept that a person has a duty to exercise reasonable care and diligence in the performance of obligations to another

Scienter

—commission of an act with knowledge or intent to deceive

Securities Act of 1933

—a federal statute dealing with companies that register and sell securities to the public; under the statute, third parties who are original purchasers of securities may recover damages from the auditor if the financial statements are misstated, unless the auditor proves that the audit was adequate or that the third party’s loss was caused by factors other than misleading financial statements

Securities Exchange Act of 1934

—a federal statute dealing with companies that trade securities on national and over-the-counter exchanges; auditors are involved because the annual reporting requirements include audited financial statements

Ultramares doctrine

—a common-law approach to third-party liability, established in 1931 in the case ofUltramares Corporation v. Touche, in which ordinary negligence is insufficient for liability to third parties because of the lack of privity of contract between the third party and the auditor, unless the third party is a primary beneficiary