# Group Audits: How Component Auditors Work for Malaysian Subsidiaries

> How a group auditor scopes, directs and relies on the component auditors of Malaysian subsidiaries under ISA 600 (Revised), which MIA's Auditing and Assurance Standards Board adopts as a Malaysian Approved Standard on Auditing without modification.

- Category: audit
- Language: en
- Status: published
- Updated: 2026-08-08
- Canonical: https://negaraku.md/en/audit/group-audit-component-auditors-malaysia

---

A German parent consolidates its Kuala Lumpur trading arm, but the group's audit partner in Frankfurt has never set foot in Malaysia and does not read the local ledgers. Someone in Malaysia does the fieldwork — yet the signature on the group opinion is still the group partner's alone. That split is exactly what the group-audit standard is built to govern.

## Who does what in a cross-border group audit?

In a group audit, one firm holds the group engagement — and the partner leading it, the **group engagement partner**, is answerable for the opinion on the consolidated (group) financial statements. Individual entities inside the group are **components**: subsidiaries, branches, divisions, joint arrangements, even shared-service centres. When a separate firm audits a component, that firm is the **component auditor**.

The pivotal change under ISA 600 (Revised) is that the component auditor is no longer an outsider whose work is merely "relied upon". Aligned with ISA 220 (Revised) on quality management, component auditors are now treated as members of a single **group engagement team**. The group engagement partner must direct, supervise and review their work, with access to their documentation — not just collect a clearance memo at the end.

| Role | Who it is | Core responsibility |
| --- | --- | --- |
| Group engagement partner | Partner at the group audit firm | Sole responsibility for the group audit opinion; sufficient involvement in component work |
| Group engagement team | Group partner + staff, now including component auditors | Plans the group audit, sets group materiality, performs consolidation procedures |
| Component auditor | Local firm auditing a component (e.g. the Malaysian subsidiary) | Performs assigned work on the component under group-team direction |
| Component (Malaysian subsidiary) | The audited entity | Provides information for both its statutory and the group audit |

## What changed under ISA 600 (Revised)?

The revised standard, issued by the IAASB and effective for audits of group financial statements for periods beginning on or after **15 December 2023**, moves from a size-driven approach to a risk-driven one.

| Superseded ISA 600 | ISA 600 (Revised) |
| --- | --- |
| Split components into "significant" vs "non-significant" by size or risk threshold | Removes the "significant component" distinction entirely |
| Scoping largely a function of component size | Scoping driven by assessed risks of material misstatement at the group level |
| Component auditor treated as a party whose work is relied on | Component auditor is part of the group engagement team |
| Lighter explicit link to other standards | Strong linkage to ISQM 1, ISA 220 (Revised), ISA 315 (Revised 2019) and ISA 330 |

Two concepts do the heavy lifting. **Aggregation risk** recognises that many individually immaterial misstatements across components can, added together, be material to the group. And **component performance materiality** lets the group team set a tighter materiality for higher-risk components so that aggregation risk stays controlled. Neither depends on how large a subsidiary is.

## How the group auditor scopes a Malaysian subsidiary

Rather than asking "is this subsidiary big enough to audit?", the group team asks "what risks of material misstatement in the group statements arise here, and what work responds to them?" Depending on that answer, the Malaysian component might get a full audit of its financial information, specified procedures on particular balances, or only group-level analytical procedures.

Communication runs both ways and at every stage:

- **Planning** — the group team sends the component auditor group materiality, identified risks (including fraud and related-party risks), and instructions.
- **Execution** — the component auditor reports misstatements above the threshold, suspected fraud and significant control deficiencies on a timely basis, not just at the end.
- **Completion** — the component auditor confirms the work done and its sufficiency, and the group team documents its response.

If the group auditor cannot get access to a Malaysian component auditor's people, records or working papers, and the component matters to the group numbers, the group auditor may lack sufficient appropriate evidence — which can force a qualified opinion or a disclaimer of opinion.

## Where Malaysia fits in

Malaysia's Auditing and Assurance Standards Board (AASB), within the Malaysian Institute of Accountants (MIA), adopts the pronouncements issued by the IAASB as the Malaysian Approved Standards on Quality Management, Auditing, Review, Other Assurance and Related Services, without modification. So a Malaysian audit firm acting as component auditor applies the same ISA 600 (Revised) text as the group team abroad.

Separately, the Malaysian subsidiary's own statutory audit must be conducted by an approved company auditor under the Companies Act 2016 — that person is often the natural component auditor for the group. A company that fails to lodge its audited financial statements with the Companies Commission of Malaysia (SSM) within the statutory period commits an offence: under section 259 of the Companies Act 2016, the company and every officer in default is liable to a fine not exceeding **RM50,000**, and, for a continuing offence, a further fine not exceeding **RM1,000** for each day the offence continues. The local audit therefore has to happen regardless of the group timetable.

## What's next

If you are a **group team** with a Malaysian component, brief the local auditor early with group materiality and risk assessments, and confirm you will have access to their files before you commit to relying on their work. If you are a **Malaysian firm** taking on component work, expect to be treated as part of the group engagement team — direction, supervision and review included — and price the two-way communication accordingly. Read this alongside the profiles of the [approved company auditor regime](/en/audit/approved-company-auditor-malaysia) and the [Malaysian Institute of Accountants](/en/audit/malaysian-institute-of-accountants) for the local licensing and standard-setting picture.

## Sources

- International Standard on Auditing 600 (Revised), Special Considerations—Audits of Group Financial Statements (Including the Work of Component Auditors) — https://www.iaasb.org/publications/international-standard-auditing-600-revised-special-considerations-audits-group-financial-statements (IAASB)
- Malaysia — Member Country Profile (adoption of IAASB pronouncements by MIA's Auditing and Assurance Standards Board) — https://www.ifac.org/about-ifac/membership/profile/malaysia (IFAC)
- Companies Act 2016 (Act 777) — https://www.ssm.com.my/Pages/Legal_Framework/Document/Companies%20Act%202016_Akta%20777_BI%20(1.8.2022).pdf (Companies Commission of Malaysia (SSM))
- Key Requirements of the Malaysian Companies Act 2016 — Annual Return, Financial Statements and AGM (penalty under s259) — https://www.datamet.com.my/regulatory-updates-newsletters/key-requirements-of-the-malaysian-companies-act-2016-annual-return-financial-statements-and-annual-general-meeting/ (Datamet Merchant Consultants)
- ISA 600: What's New in Group Audits? — https://ccs-co.com/post/isa-600-what-s-new-in-group-audits/ (CCS & Co (Chartered Accountants))
- ISA 600 (Revised) — Special Considerations: Audits of Group Financial Statements: Complete Guide — https://ciferi.com/blog/isa-600-group-audits-guide/ (Ciferi)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
