When a multinational consolidates a Malaysian subsidiary, the group engagement partner remains solely responsible for the group audit opinion but can draw on a local component auditor to do the work. ISA 600 (Revised) governs how that relationship works. Malaysia's Auditing and Assurance Standards Board (AASB), within the Malaysian Institute of Accountants (MIA), adopts IAASB pronouncements as Malaysian Approved Standards on Auditing without modification, so the same text applies locally. The revised standard replaces the old size-based 'significant component' test with a risk-based scoping approach, treats component auditors as part of one engagement team, and is effective for group financial statements for periods beginning on or after 15 December 2023.
- ISA 600 (Revised) is effective for audits of group financial statements for periods beginning on or after 15 December 2023, with earlier application permitted.
- The revised standard removes the 'significant component' distinction and scopes components by assessed risk of material misstatement, not by size threshold.
- Component auditors are now treated as members of the group engagement team under ISA 220 (Revised), not merely third parties whose work is 'relied upon'.
- The group engagement partner keeps overall responsibility, and must direct, supervise and review the component auditor's work with sufficient access to their documentation.
- MIA's Auditing and Assurance Standards Board adopts IAASB pronouncements as Malaysian Approved Standards on Auditing without modification, so ISA 600 (Revised) applies to Malaysian audits in the same form.
Who this applies to: Group engagement teams at multinational parents, Malaysian audit firms acting as component auditors, and finance teams of Malaysian subsidiaries within a foreign group.
On this page
A German parent consolidates its Kuala Lumpur trading arm, but the group’s audit partner in Frankfurt has never set foot in Malaysia and does not read the local ledgers. Someone in Malaysia does the fieldwork — yet the signature on the group opinion is still the group partner’s alone. That split is exactly what the group-audit standard is built to govern.
Who does what in a cross-border group audit?
In a group audit, one firm holds the group engagement — and the partner leading it, the group engagement partner, is answerable for the opinion on the consolidated (group) financial statements. Individual entities inside the group are components: subsidiaries, branches, divisions, joint arrangements, even shared-service centres. When a separate firm audits a component, that firm is the component auditor.
The pivotal change under ISA 600 (Revised) is that the component auditor is no longer an outsider whose work is merely “relied upon”. Aligned with ISA 220 (Revised) on quality management, component auditors are now treated as members of a single group engagement team. The group engagement partner must direct, supervise and review their work, with access to their documentation — not just collect a clearance memo at the end.
| Role | Who it is | Core responsibility |
|---|---|---|
| Group engagement partner | Partner at the group audit firm | Sole responsibility for the group audit opinion; sufficient involvement in component work |
| Group engagement team | Group partner + staff, now including component auditors | Plans the group audit, sets group materiality, performs consolidation procedures |
| Component auditor | Local firm auditing a component (e.g. the Malaysian subsidiary) | Performs assigned work on the component under group-team direction |
| Component (Malaysian subsidiary) | The audited entity | Provides information for both its statutory and the group audit |
What changed under ISA 600 (Revised)?
The revised standard, issued by the IAASB and effective for audits of group financial statements for periods beginning on or after 15 December 2023, moves from a size-driven approach to a risk-driven one.
| Superseded ISA 600 | ISA 600 (Revised) |
|---|---|
| Split components into “significant” vs “non-significant” by size or risk threshold | Removes the “significant component” distinction entirely |
| Scoping largely a function of component size | Scoping driven by assessed risks of material misstatement at the group level |
| Component auditor treated as a party whose work is relied on | Component auditor is part of the group engagement team |
| Lighter explicit link to other standards | Strong linkage to ISQM 1, ISA 220 (Revised), ISA 315 (Revised 2019) and ISA 330 |
Two concepts do the heavy lifting. Aggregation risk recognises that many individually immaterial misstatements across components can, added together, be material to the group. And component performance materiality lets the group team set a tighter materiality for higher-risk components so that aggregation risk stays controlled. Neither depends on how large a subsidiary is.
How the group auditor scopes a Malaysian subsidiary
Rather than asking “is this subsidiary big enough to audit?”, the group team asks “what risks of material misstatement in the group statements arise here, and what work responds to them?” Depending on that answer, the Malaysian component might get a full audit of its financial information, specified procedures on particular balances, or only group-level analytical procedures.
Communication runs both ways and at every stage:
- Planning — the group team sends the component auditor group materiality, identified risks (including fraud and related-party risks), and instructions.
- Execution — the component auditor reports misstatements above the threshold, suspected fraud and significant control deficiencies on a timely basis, not just at the end.
- Completion — the component auditor confirms the work done and its sufficiency, and the group team documents its response.
If the group auditor cannot get access to a Malaysian component auditor’s people, records or working papers, and the component matters to the group numbers, the group auditor may lack sufficient appropriate evidence — which can force a qualified opinion or a disclaimer of opinion.
Where Malaysia fits in
Malaysia’s Auditing and Assurance Standards Board (AASB), within the Malaysian Institute of Accountants (MIA), adopts the pronouncements issued by the IAASB as the Malaysian Approved Standards on Quality Management, Auditing, Review, Other Assurance and Related Services, without modification. So a Malaysian audit firm acting as component auditor applies the same ISA 600 (Revised) text as the group team abroad.
Separately, the Malaysian subsidiary’s own statutory audit must be conducted by an approved company auditor under the Companies Act 2016 — that person is often the natural component auditor for the group. A company that fails to lodge its audited financial statements with the Companies Commission of Malaysia (SSM) within the statutory period commits an offence: under section 259 of the Companies Act 2016, the company and every officer in default is liable to a fine not exceeding RM50,000, and, for a continuing offence, a further fine not exceeding RM1,000 for each day the offence continues. The local audit therefore has to happen regardless of the group timetable.
What’s next
If you are a group team with a Malaysian component, brief the local auditor early with group materiality and risk assessments, and confirm you will have access to their files before you commit to relying on their work. If you are a Malaysian firm taking on component work, expect to be treated as part of the group engagement team — direction, supervision and review included — and price the two-way communication accordingly. Read this alongside the profiles of the approved company auditor regime and the Malaysian Institute of Accountants for the local licensing and standard-setting picture.
When did ISA 600 (Revised) take effect in Malaysia?
It is effective for audits of group financial statements for periods beginning on or after 15 December 2023, with earlier application permitted. Because MIA's Auditing and Assurance Standards Board adopts IAASB pronouncements without modification, the Malaysian standard carries the international text.
Can the Malaysian subsidiary's local auditor sign off the group opinion?
No. The component auditor performs work on the Malaysian subsidiary, but the group engagement partner retains sole responsibility for the group audit opinion and must be sufficiently involved in the component auditor's work.
What happens if the group auditor cannot access the Malaysian component auditor's files?
If access to component information or auditors is restricted and the component is significant, the group auditor may be unable to obtain sufficient appropriate evidence, which can lead to a qualified opinion or a disclaimer of opinion on the group financial statements.
The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:
- Confirm the Companies Act 2016 section (s259) and the current fine figures (up to RM50,000, plus RM1,000/day for a continuing offence) against the official SSM-published Act text.
- Confirm MIA/AASB has adopted ISA 600 (Revised) specifically with the 15 December 2023 effective date; IFAC confirms adoption without modification in general, but a MIA effective-date circular for ISA 600 (Revised) should be sighted.
- Confirm whether the specific Malaysian subsidiary in scope qualifies for any audit exemption (certain dormant/threshold-qualifying private companies) before assuming a statutory audit is required.
Sources
- International Standard on Auditing 600 (Revised), Special Considerations—Audits of Group Financial Statements (Including the Work of Component Auditors) — IAASB
- Malaysia — Member Country Profile (adoption of IAASB pronouncements by MIA's Auditing and Assurance Standards Board) — IFAC
- Companies Act 2016 (Act 777) — Companies Commission of Malaysia (SSM)
- Key Requirements of the Malaysian Companies Act 2016 — Annual Return, Financial Statements and AGM (penalty under s259) — Datamet Merchant Consultants
- ISA 600: What's New in Group Audits? — CCS & Co (Chartered Accountants)
- ISA 600 (Revised) — Special Considerations: Audits of Group Financial Statements: Complete Guide — Ciferi
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 8 Aug 2026 | Approved and published. | — |