Welcome to Corporate Governance!
Hello there! Welcome to one of the most important chapters in your Professional Level – Business Assurance journey. You might think "Corporate Governance" (CG) sounds like a dry topic full of rules and regulations, but it’s actually the "heartbeat" of a healthy company. Think of it as the rules of the game that ensure a company is run fairly, honestly, and successfully. For an auditor, understanding these practices is vital because if the governance is weak, the risk of "funny business" or errors in the financial statements goes way up!
In this chapter, we will explore how companies are directed and controlled, focusing specifically on the Hong Kong Corporate Governance Code. Don’t worry if this seems tricky at first—we’ll break it down piece by piece!
1. The Core Philosophy: "Comply or Explain"
In Hong Kong, the Corporate Governance Code isn't a strict "law" in the sense that you go to jail if you miss a minor detail. Instead, it operates on a "Comply or Explain" basis.
What does this mean?
Listed companies are expected to follow the "Code Provisions." If they choose not to follow a specific rule (perhaps because they are a small startup and the rule is too expensive), they must explain exactly why they didn't follow it in their annual report. This keeps them transparent and accountable to their shareholders.
Quick Review:
- Mandatory Disclosure: Some things must be reported.
- Code Provisions: Comply or explain.
- Recommended Best Practices: Encouraged, but voluntary disclosure.
Analogy: Think of it like a school dress code. You are expected to wear the uniform (Comply). If you show up in a hoodie because your sweater is in the wash, you must bring a note from your parents explaining why (Explain).
2. The Brain of the Company: The Board of Directors
The Board of Directors is responsible for the leadership and control of the company. A good board should have a balance of skills, experience, and independence.
Executive vs. Non-Executive Directors
It is important to understand the two "types" of people sitting at the board table:
1. Executive Directors (EDs): These are the "insiders." They work at the company full-time (like the CEO or CFO) and handle daily operations.
2. Non-Executive Directors (NEDs): These are "outsiders." They don't work there daily. Their job is to provide objective advice and "keep an eye" on the EDs.
3. Independent Non-Executive Directors (INEDs): These are a special type of NED. They must have no business or family ties to the company. They are the "watchdogs" for the minority shareholders.
Key Rule to Remember:
Under HK Listing Rules, at least one-third of the board should be INEDs, and there must be a minimum of three INEDs. At least one INED must have appropriate professional qualifications or accounting/financial management expertise.
Did you know?
The reason we need an accountant on the board is to ensure someone actually understands the "nitty-gritty" of the financial reports before they are signed off!
3. Separation of Power: Chairman vs. CEO
A very common exam point is the segregation of duties at the top. The roles of the Chairman and the Chief Executive Officer (CEO) should be separate and should not be performed by the same person.
Why?
- The Chairman runs the Board (focuses on governance and meetings).
- The CEO runs the Business (focuses on profits and operations).
If one person does both, they have too much power! It’s like being the Judge and the Prosecutor at the same time.
4. The Board Committees: The "Specialist Teams"
The Board is too busy to handle every detail, so they delegate specific tasks to Committees. As an Assurance student, you need to know these four:
A. The Audit Committee (The Most Important for You!)
This committee acts as the bridge between the external auditor (you!) and the Board.
- Who is in it? Only NEDs, and a majority must be Independent (INEDs).
- What do they do? They monitor the integrity of financial statements, oversee internal controls, and recommend the appointment of the external auditor.
B. The Remuneration Committee
- The Goal: To ensure directors are paid enough to be motivated, but not so much that they are "robbing" the shareholders.
- Key Rule: No director should be involved in deciding his or her own pay!
C. The Nomination Committee
- The Goal: To find the right people to join the board. They look at "Diversity" (gender, age, experience) to make sure the board isn't just a "boys' club" of friends.
D. The Risk Committee
- The Goal: To identify what could go wrong (e.g., cyber-attacks, market crashes) and ensure the company has a plan to handle it.
Memory Aid: "A-R-N-R"
Audit, Remuneration, Nomination, Risk. These are the four pillars of board oversight.
5. Internal Controls and Risk Management
The Board is ultimately responsible for the company’s Internal Control Systems. They must conduct a review of the effectiveness of these systems at least annually.
Assurance Link:
As an auditor, if you see that the Board hasn't reviewed their controls or doesn't have an Internal Audit (IA) function, your Control Risk assessment will be high. You’ll need to do more "substantive testing" (checking more invoices and receipts) because you can't trust the company's internal systems.
6. Engagement with Shareholders
Corporate governance isn't just about the board; it's about the owners (shareholders).
- Companies should have a Shareholders' Communication Policy.
- The Annual General Meeting (AGM) is the primary place for directors to face the shareholders and answer their questions.
Summary and Key Takeaways
Before you move on, make sure you have these points locked in:
1. Balance is Key: You need a mix of EDs and INEDs (at least 1/3 INEDs).
2. Split the Top: Don't let the Chairman and CEO be the same person.
3. The Audit Committee is your friend: They are your main point of contact during an audit and must be independent.
4. Comply or Explain: Flexibility exists, but transparency is mandatory.
5. Annual Review: Internal controls must be checked by the board every year.
Common Mistake to Avoid:
Don't confuse Internal Audit with the Audit Committee.
- Internal Audit is a department of employees who check things daily.
- The Audit Committee is a group of high-level Board Directors who oversee everything (including the Internal Auditors).
Great job! You’ve just mastered the essentials of Corporate Governance Practices. This foundation will help you immensely when we start discussing "Risk Assessment" in later chapters. Keep going!