# Auditor's Statutory Duty to Report Breaches to the SSM

> Under section 266 of the Companies Act 2016, an auditor is required to report breaches of the Act or serious fraud offences directly to the Registrar (SSM) — a duty that is separate from the audit opinion itself.

- Category: audit
- Language: en
- Status: published
- Updated: 2026-08-08
- Canonical: https://negaraku.md/en/audit/auditor-duty-to-report-breaches

---

An auditor who uncovers fraud during an audit cannot simply stay silent and sign off on the report — the law requires a written report to the Registrar. This duty is not optional, and ignoring it is itself a crime.

## Which provision governs this duty?

The auditor's statutory duty to report breaches is contained in **section 266 of the Companies Act 2016** (Powers and duties of auditors) — not section 340, which is frequently cited by mistake. Two subsections form the backbone of the reporting duty to the Registrar (the Companies Commission of Malaysia, SSM):

- **Section 266(8)** — a breach of or non-compliance with any provision of the Act.
- **Section 266(9)** — a serious offence involving fraud or dishonesty in a public company.

## When must an auditor report to the SSM?

Under **section 266(8)**, where the auditor is satisfied that there has been a breach of or non-compliance with any provision of the Act, and the circumstances are such that in his opinion the matter **has not been or will not be adequately dealt with** by comment in the audit report or by bringing the matter to the attention of the directors, he shall **immediately report the matter in writing** to the Registrar.

This means the duty to report arises not on every minor breach, but when the usual channels — the audit report and notifying the board — are inadequate.

Under **section 266(9)**, if the auditor of a public company (or a company controlled by a public company) is of the opinion that a **serious offence involving fraud or dishonesty** is being or has been committed against the company or the Act by an officer of the company, he shall immediately report the matter in writing to the Registrar.

## What does "serious offence" mean?

Section 266(11)(b) sets a clear, numerical threshold:

| Criterion | Threshold |
| --- | --- |
| Imprisonment penalty for the offence | Not less than **two years** |
| Value of assets or loss suffered by the company, members or debenture holders | Exceeds **RM250,000** |

Meeting either criterion is enough to categorise an offence as "serious" for reporting purposes. The definition also specifically includes offences under sections 591, 592, 593, 594 and 595 of the Act.

## Is an auditor exposed to action for reporting?

For reporting under section 266(9), no. **Section 266(10)** provides an important protection: no duty to which an auditor may be subject is taken to be contravened merely because he reports **a matter referred to in subsection (9)** in good faith to the Registrar. This protection helps resolve the conflict between the duty of confidentiality to the client and the public duty to report.

It should be noted that this express statutory protection is referred specifically to reports under **subsection (9)** only. Section 266(10) does not expressly provide an equivalent protection for reports of breaches under **subsection (8)** — a difference in scope that a lawyer should review for a particular situation.

## What are the consequences if an auditor fails to report?

Under **section 266(13)**, any auditor who contravenes subsection (8) or (9) commits an offence. On conviction, the auditor is liable to:

- **imprisonment for up to five (5) years**, or
- **a fine of up to RM3 million**, or
- **both**.

The reporting duties under sections 266(8) and (9) apply to the auditor separately; the directors' responsibility for the financial statements does not replace or discharge the auditor's statutory duty to report.

## What's next

- Read the full text of **section 266 of the Companies Act 2016** to understand the subsections relating to the power to access records and the other reporting duties.
- Review the audit practice guidance issued by the Malaysian Institute of Accountants (MIA) for the operational procedures when a breach is found during an audit.
- Understand the relationship between this duty and the principle of auditor independence under Malaysia's corporate governance framework.

## Sources

- Companies Act 2016 (Act 777) — Section 266, Powers and duties of auditors (teks statut rasmi, cetakan semula 1.8.2022) — https://www.ssm.com.my/Pages/Legal_Framework/Document/Companies%20Act%202016_Akta%20777_BI%20(1.8.2022).pdf (Suruhanjaya Syarikat Malaysia (SSM))
- Laws of Malaysia — Act 777, Companies Act 2016 (online updated text of reprint, 1.8.2022) — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/1738979_BI/Act%20777-%20Final%20Draft%20(1.8.2022).pdf (Attorney General's Chambers of Malaysia (AGC), Federal Legislation Portal)
- Duties and Responsibilities of Auditors in relation to the Company's Financial Statements and Accounting Records — https://www.thomasphilip.com.my/articles/duties-and-responsibilities-of-auditors-in-relation-to-the-companyrs-financial-statements-and-accounting-records/ (Thomas Philip Advocates and Solicitors)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
