FRC Audit Sanctions Show Why Independence and Internal Assurance Matter
What happened?
The UK’s Financial Reporting Council (FRC) has fined audit firm King & King and its managing partner following a four-year investigation into audits carried out for companies within Sanjeev Gupta’s GFG Alliance. The regulator found widespread deficiencies in more than 140 audits, including failures relating to auditor independence, planning, risk assessment and financial reporting. It also concluded that the firm’s dependence on fees from one client group created serious ethical concerns.
While this case relates to statutory external audit, the wider lesson applies to every organisation.
Whether you operate in the private sector, public sector or voluntary sector, assurance only has value when it is objective, evidence-based and independent enough to challenge poor practice.
Why this matters
Many organisations think of audit as something that happens once a year.
In reality, effective assurance is an ongoing process.
Boards, leadership teams and business owners rely on accurate information to make decisions. If controls are weak, risks are poorly understood or challenge is absent, problems can remain hidden until they become operational, financial or reputational issues.
The FRC’s findings demonstrate why independence matters. When assurance becomes too closely linked to commercial interests or existing relationships, the quality of challenge can suffer. That creates risk not only for auditors, but also for organisations relying on assurance to support important decisions.
The principle extends beyond financial audits.
Internal audit, governance reviews, compliance monitoring, supplier assurance, health and safety inspections, cyber assessments and ESG reviews all depend on the same foundations:
-
Independence.
-
Professional judgement.
-
Reliable evidence.
-
Transparent reporting.
-
Clear accountability.
Strong assurance helps organisations identify issues early, improve controls and build confidence with regulators, clients, investors and procurement teams.
Weak assurance often creates a false sense of security.
What good looks like
Good assurance begins with strong governance.
Leadership should understand which risks matter most, who owns them and how independent assurance reaches decision-makers.
Effective internal assurance frameworks normally include:
-
A current risk register.
-
Internal audit planning.
-
Policy review schedules.
-
Control testing.
-
Incident and complaints analysis.
-
Financial control reviews.
-
Supplier assurance.
-
Board reporting.
-
Action tracking and follow-up.
Evidence is critical.
Every recommendation should be supported by documented findings, and every agreed action should have a named owner and target completion date.
Challenge is equally important.
Good assurance should ask difficult questions where necessary. The purpose is not to criticise, but to improve organisational resilience, governance and performance.
Organisations that welcome independent review often identify weaknesses before customers, regulators or external auditors do.
What to do now
Small businesses and SMEs
Review your key business risks and internal controls. Even a simple annual independent review can identify issues that routine management may overlook.
Medium-sized organisations
Establish a structured internal assurance programme covering finance, operations, compliance, cyber security, suppliers and health and safety.
Large organisations and multi-site businesses
Assess whether assurance remains genuinely independent. Review reporting lines, audit coverage and whether recommendations are consistently implemented across all locations.
Public sector organisations
Ensure assurance work supports transparency, accountability and value for money. Boards and audit committees should receive meaningful reports focused on risks and improvement actions.
Contractors and suppliers
Expect clients to ask more questions about governance and assurance. Maintain evidence of internal reviews, policy compliance, risk management and continuous improvement.
How TPMG helps
TPMG supports organisations through Internal Audit & Risk Assurance, Governance Reviews, Public Sector Advisory, Contractor Advisory, Policy Review and Risk Management services.
We provide practical, independent assurance that helps organisations strengthen governance, improve controls and build confidence with clients, regulators and stakeholders.
Our reviews focus on evidence rather than assumptions, helping leadership teams understand where risks exist, how controls are performing and where improvements should be prioritised.
TPMG can provide an independent Internal Audit and Risk Assurance review to identify governance gaps, strengthen control frameworks and improve organisational confidence before external scrutiny highlights weaknesses.