Editor’s Note
After exploring the regulatory evolution, core disputes, and the criteria for distinguishing between ordinary negligence and gross negligence in the determination of fault in accounting firm false statement cases, theoretical analysis must be grounded in vivid judicial practice. To intuitively demonstrate how the aforementioned theoretical framework and judgment path are applied to complex realities, this article will analyze the liability determination of Ruihua Certified Public Accountants in the dispute over compensation for torts caused by false statements involving “China Security Co., Ltd.” (Zhonganke). The following text will strictly follow the reverse analysis path of “detecting signs of fraud → examining risk response → evaluating whether risk identification was reasonable,” reviewing auditing behaviors layer by layer, aiming to provide a referable empirical footnote for the judicial determination of “ordinary negligence” and “gross negligence.”
Case Background
In 2014, China Security Co., Ltd. (formerly known as “China Security Fire Co., Ltd.” and “Shanghai Feilo Co., Ltd.”) implemented a major asset restructuring, purchasing 100% of the equity held in China Security Fire Technology Co., Ltd. by issuing shares to Shenzhen Zhongheng Huizhi Investment Co., Ltd. Ruihua Certified Public Accountants served as the auditing institution for this major asset restructuring. Later, the China Securities Regulatory Commission (CSRC) found that the target asset, China Security Fire Technology, had committed false statements, involving the inflation of operating income for the 2013 fiscal year through the “Smart Shiguai” project. Key facts included: 1. The timing of revenue recognition (December 2013) preceded the project bidding time (March 2014); 2. The “Project Progress Completion Confirmation Form,” a key basis for revenue recognition, lacked the seal of the supervision unit, and the authenticity of the government official seal was questionable; 3. The project did not meet construction conditions at the end of 2013; 4. There was uncertainty regarding the contract price.
I. Detecting Signs of Fraud
The core of auditing work lies in initiating and deepening verification procedures based on “signs.” The determination of the negligence scenarios listed in Article 6 of the “Several Provisions on the Trial of Civil Compensation Cases Involving Audit Torts” must ultimately return to whether the accountant maintained “necessary professional skepticism.” In voluminous audit working papers, clues to errors and fraud are not always obvious. In this case, when auditing the “Smart Shiguai” project, the accountant should have at least noticed two obvious and contradictory “signs”:
Sign 1 (Contradictory Evidence): Inconsistency between bidding time and revenue recognition time
Revenue was recognized in December 2013, while project bidding began in March 2014. This constitutes “contradictory evidence” that should trigger professional skepticism as referred to in Article 30 of the “Basic Standards for Assurance Engagements of Chinese Certified Public Accountants.”
Sign 2 (Questionable Reliability): The “Project Progress Completion Confirmation Form” lacked the seal of the supervision unit
The “Project Progress Completion Confirmation Form,” the core basis for revenue recognition, lacked the seal of the supervision unit. Although in the context of the time, this single flaw alone might not have been enough to directly trigger strong suspicion regarding the authenticity of the government seal, its overlap with “Sign 1” was sufficient to constitute a reasonable doubt requiring additional audit procedures for verification.
II. Response to Signs of Fraud
According to public information, in the face of the above signs, Ruihua implemented at least the following response procedures:
Response 1: Inquiring with Management
As the most direct additional procedure, the accountant inquired with management regarding the contradiction of “inconsistency between bidding time and revenue recognition time.” The explanation provided by management was that “the ‘Smart Shiguai’ project involved construction first followed by retroactive bidding procedures.” In the business practices at the time of the audit, such situations where the “bidding before construction” process was not strictly followed did indeed exist because government departments, as the tendering party, were often in a dominant position; therefore, the explanation appeared reasonable on the surface. Given that the “Project Progress Completion Confirmation Form” with the seal of the Baotou Shiguai District Government had been obtained, the accountant had reason to initially believe the project had actually commenced, and the missing seal of the supervision unit was not enough to directly negate the government’s confirmation of progress. Therefore, solely in terms of the accounting treatment for revenue recognition, it seemed reasonable in form for China Security Fire Technology to recognize revenue based on completion progress as stipulated in the contract. It must be clarified that the fact later verified by regulators—that the “government seal was not applied through normal channels”—was an extreme circumstance unforeseeable at the time of the audit, and this outcome cannot be used to retroactively conclude that the accountant was at fault during the audit process at that time.
Response 2: External Confirmation
According to the basic rules of double-entry bookkeeping, the recognition of operating income corresponds to an increase in accounts receivable. According to the mandatory provisions of Article 13 of “Chinese Certified Public Accountant Auditing Standard No. 1312 — External Confirmations,” CPAs shall perform external confirmation procedures for accounts receivable unless there is sufficient evidence that they are immaterial or that external confirmation is likely to be ineffective. The accounts receivable formed by the “Smart Shiguai” project amounted to 50 million RMB, accounting for 56.8% of the total accounts receivable in the parent company’s statements and 37.5% in the consolidated statements, making it an absolutely material item. Therefore, whether based on the rigid requirements of auditing standards or the professional skepticism that should have been triggered by the identified “time contradiction” and “evidentiary flaws,” Ruihua had an obligation to, and in fact did, perform external confirmation procedures for this account receivable. However, as external confirmation is a non-compulsory auditing procedure, especially when the confirmed party is a powerful government department, failure to receive a reply is a common difficulty in auditing practice. The key to judging whether an accountant has been diligent and responsible lies not in whether a reply was received, but in whether sufficient and appropriate alternative auditing procedures were performed when the external confirmation procedure failed to achieve the expected results. Article 19 of “Chinese Certified Public Accountant Auditing Standard No. 1312 — External Confirmations” explicitly stipulates that in the event of no reply, the CPA must implement alternative procedures to obtain relevant and reliable audit evidence. If Ruihua failed to effectively implement or completely failed to implement alternative procedures (such as verifying subsequent payments, inspecting relevant original contracts and supporting documents, etc.) after failing to receive a reply, its behavior constituted “failure to fully comply with the requirements of professional standards.” Although such behavior is flawed, it has not reached the level of “completely failing to follow professional standards or failing to perform the audit according to basic requirements,” and in terms of the nature of the fault, it should lean toward being identified as ordinary negligence rather than gross negligence.
III. Whether the Response was Sufficient: A Re-examination Based on Overall Risk Assessment
In summary, Ruihua did indeed implement response measures such as inquiries and external confirmations regarding the identified doubts. However, in the presence of two abnormal signs—”chronological contradiction” and “flaws in key evidence”—was merely conducting an inquiry and obtaining a seemingly reasonable explanation, along with potentially missing alternative procedures after a failed confirmation, sufficient to reasonably ensure that the accountant had been diligent and had eliminated all material doubts? The sufficiency of an audit response cannot be judged in isolation from the specific auditing environment. Under the risk-oriented audit model, an auditor’s judgment on the depth and breadth of the execution of specific procedures fundamentally stems from their assessment of the overall risk of material misstatement of the audited entity. Therefore, the aforementioned specific response measures must be re-evaluated within the macro risk context of China Security Fire Technology and this specific transaction:
Risk 1: Risks Associated with the Special Background of a Backdoor Listing
The transaction in this case was essentially a “backdoor listing,” which is a faster process compared to a normal IPO, with relatively relaxed regulatory inquiries and guidance periods. This provides convenience for asset owners intending to evade the strict scrutiny of an IPO and significantly increases the motivation for “shell companies” to window-dress their financial statements to boost valuations. The target assets themselves often have questionable quality or going-concern capabilities. For auditors, a backdoor listing project implies higher inherent risk; investors rely heavily on restructuring information, making the role of the audit report even more critical. Accountants should maintain a higher level of professional skepticism and implement more prudent auditing procedures.
Risk 2: Profitability Risks of Using M to Inflate Revenue
The actual controller and core assets of China Security Fire Technology exhibit distinct characteristics of capital operation. Its predecessor, CSST, had been listed in various locations and conducted numerous mergers and acquisitions. The core assets injected into the listed company this time were also entirely derived from acquisitions; the company lacked organic growth of core entities and endogenous competitiveness. This model of stacking revenue and profit primarily through capital M, while capable of beautifying consolidated statements in the short term, does not truly enhance the enterprise’s going-concern capability and may provide operational space for manipulating the timing of consolidated statements and inflating performance, constituting significant risks to profitability and the authenticity of performance.
Risk 3: Internal Control Risks of Concentrated Ownership and Long-term Absence of Internal Bodies Historically
After this backdoor listing, the actual controller, Tu Guoshen, indirectly controlled approximately 40.98% of China Security Fire’s equity through Zhongheng Huizhi, forming a “dominant shareholder” ownership structure. Prior to the transaction, the target company’s governance structure was extremely imperfect, with no board of supervisors or independent directors established for a long time. Even if the “three meetings” (shareholders, directors, and supervisors) were established in form after the restructuring to meet regulatory requirements, there were major doubts as to whether they could operate effectively and form substantive checks and balances in the context of a lack of long-term IPO guidance and highly concentrated ownership. A weak internal control environment is a breeding ground for financial statement fraud, significantly increasing the risk of material misstatement at the financial statement level.
Risk 4: Special Risks in Revenue Recognition Auditing
Article 27 of “Chinese Certified Public Accountant Auditing Standard No. 1141 — The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements” establishes the presumptive requirement that “there are risks of fraud in revenue recognition.” This means that during the risk assessment stage, the CPA must preset the area of revenue recognition as having the possibility of fraud and prudently evaluate specific risk points accordingly. It should be clarified that this presumption does not require questioning all revenue recognition indiscriminately, but emphasizes that auditing work must combine an in-depth understanding of the audited entity’s specific environment, motivations, and pressures to accurately judge the ways and links where fraud might occur. Specifically in the case of Ruihua auditing China Security Fire, the following factors collectively amplified the risk level of revenue recognition:
1) The contradiction between industry competitive disadvantage and abnormally high growth. The security industry in which China Security Fire operates is highly concentrated, with giants like Hikvision and Dahua Technology having formed market monopolies. China Security Fire was at a distinct disadvantage in terms of revenue scale (approx. 1.5 billion RMB in 2014), technical accumulation, and brand influence. However, inconsistent with this industry competitive position, its net profit growth rate during the reporting period was extraordinarily alarming: 47.35% in 2012, and as high as 105.95% in 2013. In the absence of significant core technological breakthroughs or market expansion support, such extraordinary profit growth strongly suggested the possibility of inflating profits to support the backdoor listing valuation. Although subsequent profit forecasts showed a slowdown in growth, maintaining a growth rate of around 30% on an already high base was equally questionable in terms of feasibility and reasonableness.
2) Rigid profit pressure brought by the backdoor listing. This restructuring used the future income method for valuation and was accompanied by a clear performance commitment compensation agreement. According to Article 35 of the “Administrative Measures for the Major Asset Restructuring of Listed Companies,” the target assets must achieve profit forecasts in the next three years; otherwise, the counterparty must provide compensation. This gambling mechanism objectively brought strong motivation and pressure to the target company’s management to boost performance in the short term, providing a direct incentive to achieve forecast targets through early revenue recognition or even fictitious revenue.
3) The MA model and the abrupt improvement in profitability indicators. As mentioned earlier, China Security Fire’s assets and growth relied heavily on external MA, and its endogenous competitiveness was questionable. However, financial data showed that while its gross profit margin and net profit margin were significantly lower than industry leaders in 2011-2012, its net profit margin (17.21%) rose sharply against the trend in 2013, even approaching the level of industry leader Dahua Technology (20.89%). Against a background where core competitiveness had not fundamentally changed and the industry environment had seen no favorable sudden shifts, this “leapfrog” improvement in profitability achieved through MA integration constituted a major fraud risk signal regarding its authenticity and sustainability.
In conclusion, risk-oriented auditing requires that specific auditing procedures be judged within the context of overall risk. Auditing is a logically coherent and organic process. The determination of an accountant’s fault must never look at a single procedure or sign in isolation or fragmentation, but must comprehensively consider whether their professional judgment throughout the entire process of risk identification, assessment, and response was prudent and adequate.
IV. Determination of Fault for Ruihua Certified Public Accountants
The starting point for triggering additional audit procedures by an accountant is specific “suspicious signs,” but how to respond to these signs and judge whether the evidence obtained is sufficient and appropriate depends heavily on the CPA’s comprehensive assessment of the company’s overall “risk of material misstatement.” Combining the aforementioned progressive risk analysis, in this case:
It is precisely based on: (1) the heavy profit forecast pressure existing under the backdoor listing background; (2) the contradiction of lacking core advantages in a fiercely competitive industry yet showing abnormally high growth; (3) the abnormal phenomenon of relying on external MA rather than endogenous growth while profitability indicators improved abruptly; (4) governance defects where equity is highly concentrated and internal controls may be hollowed out; and (5) the inherent high-risk attribute of fraud in the field of revenue recognition.
That it can be reasonably judged: (1) management’s simple explanation of “construction first, bidding later,” in such a high-risk context, was insufficient to convincingly eliminate the major doubts brought by the contradiction in revenue recognition timing and the lack of key evidence; (2) for the extremely important account receivable of the “Smart Shiguai” project, in the event of no reply to the external confirmation sent to the government department, the accountant must implement more proactive, diverse, and in-depth alternative procedures, rather than easily accepting the explanation.
It is hereby determined: In the auditing process, Ruihua failed to give sufficient weight to specific signs within the overall high-risk context and failed to implement sufficient and appropriate further auditing procedures for the identified major doubts to obtain necessary audit evidence. Its behavior violated the spirit of Article 15 of “Chinese Certified Public Accountant Auditing Standard No. 1301 — Audit Evidence,” Articles 13 and 19 of “Chinese Certified Public Accountant Auditing Standard No. 1312 — External Confirmations,” and Article 27 of “Chinese Certified Public Accountant Auditing Standard No. 1141 — The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements,” and falls under the scenario described in Item 5, Article 6 of the “Several Provisions on the Trial of Civil Compensation Cases Involving Audit Torts”: “failure to add necessary auditing procedures upon discovering signs of possible errors and fraud.”
However, its auditing work did not completely deviate from the framework of auditing standards; it still performed basic procedures such as inquiries and sending confirmations, indicating that subjectively it had not reached a state of indifference such as “knowing full well” or “utterly disregarding,” and could still be seen as having exercised a minimum level of care. Therefore, the nature of its fault should be defined as “ordinary negligence” for failing to fully comply with professional standards, rather than “gross negligence” for fundamentally failing to follow the standards.