Yes. Section 266(8) of the Companies Act 2016 requires an auditor to report in writing to the Registrar (SSM) where there is a breach or non-compliance with any provision of the Act that would not be adequately dealt with through the audit report or by bringing it to the directors' attention. Section 266(9) further requires the immediate reporting of a serious offence involving fraud or dishonesty in a public company. Under section 266(13), an auditor who contravenes subsection (8) or (9) commits an offence punishable by imprisonment for up to 5 years or a fine of up to RM3 million or both.
- The duty to report is contained in section 266 of the Companies Act 2016, not section 340.
- Section 266(8) triggers reporting when a breach of the Act cannot be adequately dealt with through the audit report or by bringing it to the directors' attention.
- A serious offence (section 266(11)(b)) is defined as one punishable by imprisonment for not less than two years, or one involving a value/loss exceeding RM250,000.
- The good-faith protection under section 266(10) is expressly stated for reports of serious offences under subsection (9) — the Act does not expressly provide an equivalent protection for reports of breaches under subsection (8).
- A failure to report (section 266(13)) is punishable by imprisonment for up to 5 years or a fine of up to RM3 million or both.
Who this applies to: Chartered auditors, board directors, company secretaries and compliance officers in Malaysia.
On this page
An auditor who uncovers fraud during an audit cannot simply stay silent and sign off on the report — the law requires a written report to the Registrar. This duty is not optional, and ignoring it is itself a crime.
Which provision governs this duty?
The auditor’s statutory duty to report breaches is contained in section 266 of the Companies Act 2016 (Powers and duties of auditors) — not section 340, which is frequently cited by mistake. Two subsections form the backbone of the reporting duty to the Registrar (the Companies Commission of Malaysia, SSM):
- Section 266(8) — a breach of or non-compliance with any provision of the Act.
- Section 266(9) — a serious offence involving fraud or dishonesty in a public company.
When must an auditor report to the SSM?
Under section 266(8), where the auditor is satisfied that there has been a breach of or non-compliance with any provision of the Act, and the circumstances are such that in his opinion the matter has not been or will not be adequately dealt with by comment in the audit report or by bringing the matter to the attention of the directors, he shall immediately report the matter in writing to the Registrar.
This means the duty to report arises not on every minor breach, but when the usual channels — the audit report and notifying the board — are inadequate.
Under section 266(9), if the auditor of a public company (or a company controlled by a public company) is of the opinion that a serious offence involving fraud or dishonesty is being or has been committed against the company or the Act by an officer of the company, he shall immediately report the matter in writing to the Registrar.
What does “serious offence” mean?
Section 266(11)(b) sets a clear, numerical threshold:
| Criterion | Threshold |
|---|---|
| Imprisonment penalty for the offence | Not less than two years |
| Value of assets or loss suffered by the company, members or debenture holders | Exceeds RM250,000 |
Meeting either criterion is enough to categorise an offence as “serious” for reporting purposes. The definition also specifically includes offences under sections 591, 592, 593, 594 and 595 of the Act.
Is an auditor exposed to action for reporting?
For reporting under section 266(9), no. Section 266(10) provides an important protection: no duty to which an auditor may be subject is taken to be contravened merely because he reports a matter referred to in subsection (9) in good faith to the Registrar. This protection helps resolve the conflict between the duty of confidentiality to the client and the public duty to report.
It should be noted that this express statutory protection is referred specifically to reports under subsection (9) only. Section 266(10) does not expressly provide an equivalent protection for reports of breaches under subsection (8) — a difference in scope that a lawyer should review for a particular situation.
What are the consequences if an auditor fails to report?
Under section 266(13), any auditor who contravenes subsection (8) or (9) commits an offence. On conviction, the auditor is liable to:
- imprisonment for up to five (5) years, or
- a fine of up to RM3 million, or
- both.
The reporting duties under sections 266(8) and (9) apply to the auditor separately; the directors’ responsibility for the financial statements does not replace or discharge the auditor’s statutory duty to report.
What’s next
- Read the full text of section 266 of the Companies Act 2016 to understand the subsections relating to the power to access records and the other reporting duties.
- Review the audit practice guidance issued by the Malaysian Institute of Accountants (MIA) for the operational procedures when a breach is found during an audit.
- Understand the relationship between this duty and the principle of auditor independence under Malaysia’s corporate governance framework.
Does this duty apply to all companies?
The duty to report a breach of the Act under section 266(8) applies to the auditor of any company. The specific duty to report a serious offence involving fraud or dishonesty under section 266(9) applies to the auditor of a public company or a company controlled by a public company.
What does a serious offence involving fraud or dishonesty mean?
Under section 266(11)(b), it means an offence punishable by imprisonment for not less than two years, or an offence where the value of the assets or loss suffered by the company, its members or debenture holders exceeds RM250,000; it also includes offences under sections 591, 592, 593, 594 and 595.
Can an auditor be sued for reporting to the SSM?
For a report of a serious offence under section 266(9), no. Section 266(10) provides that so long as a report on a matter referred to in subsection (9) is made in good faith to the Registrar, no duty of the auditor is taken to be contravened merely because of that report. This express statutory protection is referred specifically to reports under subsection (9).
The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:
- Sahkan penomboran dan angka seksyen 266(13) (penjara sehingga 5 tahun / denda sehingga RM3 juta) terhadap cetakan semula Akta 777 yang berkuat kuasa terkini.
- Sahkan ambang kesalahan serius seksyen 266(11)(b) (2 tahun / RM250,000) tidak dipinda selepas cetakan semula bertarikh 1.8.2022.
- Semakan peguam terhadap pernyataan skop undang-undang bahawa perlindungan suci hati seksyen 266(10) terhad kepada laporan subseksyen (9) dan tidak dinyatakan secara nyata bagi laporan subseksyen (8).
Sources
- Companies Act 2016 (Act 777) — Section 266, Powers and duties of auditors (teks statut rasmi, cetakan semula 1.8.2022) — Suruhanjaya Syarikat Malaysia (SSM)
- Laws of Malaysia — Act 777, Companies Act 2016 (online updated text of reprint, 1.8.2022) — Attorney General's Chambers of Malaysia (AGC), Federal Legislation Portal
- Duties and Responsibilities of Auditors in relation to the Company's Financial Statements and Accounting Records — Thomas Philip Advocates and Solicitors
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 8 Aug 2026 | Approved and published. | — |