Single Blog Title

This is a single blog caption

What is auditing in joint-stock companies and how does it work?

 Auditing in Joint Stock Companies

Auditing, in its broadest definition, is the process of independently and expertly examining, verifying, and reporting on whether an organization's activities, financial data, and managerial decisions comply with predetermined standards, legal regulations, articles of association, and the principle of good faith. In the context of corporate law, auditing is not merely a "defect correction" process; it is a corporate "health audit" that establishes a relationship of trust between the company's legal entity, its managers (board of directors), and its shareholders.

The most distinctive feature of joint-stock companies is the separation of ownership and management. Shareholders (owners) do not manage the company themselves; they delegate this authority to the board of directors. This separation creates a risk known as the "agency problem." The board of directors may prioritize their personal interests over the company's interests, use resources inefficiently, or manipulate financial statements. The concept of auditing is the most powerful mechanism that minimizes this agency problem and has a deterrent and educational effect on the board of directors.

The Philosophical and Economic Foundations of Auditing : Auditing is more than just a legal requirement; it has economic value. An audited company is considered more trustworthy in the market. Investors, lending banks, and suppliers apply a lower risk premium to a company whose financial statements have undergone independent auditing. This reduces the cost of accessing financing for the company. Therefore, auditing is a tool that enhances a company's "reputational capital."

The fundamental elements within the concept of auditing can be grouped under four headings:

  1. Compliance Audit: Checking that operations comply with laws and internal company regulations.
  2. Financial Audit: The process of verifying that financial statements accurately reflect reality and comply with accounting standards.
  3. Performance Audit: Examining how efficient managerial decisions are and whether company resources are being used optimally.
  4. Risk Management: The identification and management of risks (financial, operational, legal) that could jeopardize the company's existence.

Fundamental Principles of the Audit Process For audits to be effective in joint-stock companies, certain fundamental principles must be implemented. First and foremost independence . The auditor should not have an organic, financial, or personal relationship with the board of directors or controlling shareholders of the company being audited. If the auditor is taking orders from the company's management, their action is not an audit, but merely an "approval mechanism." The second fundamental principle is objectivity. The auditor must make decisions based solely on data and the law, independent of emotions and biases. The third principle is transparency. Audit results should be reported in a way that is visible to shareholders and, if necessary, discussed at the general assembly.

Auditing and Corporate Governance : Auditing is central to the principles of "corporate governance." Corporate governance is built on four main pillars: fairness, transparency, accountability, and responsibility. Auditing is a fundamental discipline that supports all four pillars. A company's accountability can only be proven through auditing. If a company claims to be accountable, this should be reflected in audit reports.

The Transition from Traditional to Modern Auditing: In our old legal system, auditing was largely viewed as a formal review. However, in today's global business environment, companies have far more complex structures. Auditing that simply asks "Are they keeping the cash?" is no longer sufficient. Today, auditing has evolved to include modern-day threats such as company sustainability, environmental and social responsibility projects, digitalization risks, and cybersecurity.

Auditing is a company's "mirror." When company management looks into that mirror, they should see their true face (their successes and shortcomings). A broken mirror, or management's refusal to look in the mirror, is the biggest sign that the company is on the road to bankruptcy. In this context, auditing should be seen not as a "bureaucratic burden," but as "legal hygiene" that improves the company's quality of life.

In a joint-stock company, the concept of auditing is an institution that protects the "ownership" rights of shareholders, secures the "legal personality" existence of the company, and provides "trust" to all stakeholders. The functioning of this institution is the greatest responsibility given to joint-stock companies by the legal system.

Types of Audits

The complex structure of corporations, the diversity of risks they face, and the conflicts of interest between shareholders and management have made it impossible for a single audit model to meet every need. Accordingly, legal systems and business management literature have developed various types of audits with different purposes and focuses. Classifying audit types according to the area in which they are applied, the auditor's title, and the timing provides a deeper understanding of the subject. This classification acts as a "management toolkit," determining which tool should be used where when establishing the audit mechanism needed by the corporation.

1. Types of Audits According to Application Area

In terms of scope of application, auditing can be divided into two main categories: Financial Auditing and Operational Auditing.

  • Financial Audit: This is the auditing of a company's financial statements (balance sheet, income statement, cash flow statement, statement of changes in equity) to determine whether they comply with accounting standards and regulations, and whether they fairly reflect the truth. The primary goal of a financial audit is to provide reliable data to shareholders and the outside world (investors, banks, government). This audit is typically conducted by independent auditors and results in an "audit opinion" (positive, limited positive, negative, or no opinion).
  • Operational Audit: This type of audit goes beyond financial data. It examines how efficient, effective, and economical the company's business processes, production line, sales department, or human resources management are. Operational audits provide the board of directors with strategic recommendations to improve company performance. For example, auditing waste in a production unit or analyzing the return on investment (ROI) of the marketing budget are all subjects of operational audits.

2. Types of Audits According to the Auditor's Title

Who conducts the audit is crucial in terms of its strength and results.

  • Internal Audit: This is carried out by a unit established within the company, directly reporting to the board of directors or the audit committee. Internal auditors are employees of the company, but their professional independence must be protected. The primary task of internal audit is to continuously monitor the company's internal control systems (risk management, compliance, and internal procedures). It is the company's "self-improvement" mechanism.
  • External (Independent) Audit: This is performed by fully independent audit firms authorized by capital market authorities and operating outside the company. External audit results are the most important document proving the "accuracy" of the financial data disclosed by the company to third parties.
  • Public (State) Auditing: This refers to audits conducted by the state in the public interest. Examples include tax office audits, Capital Markets Board (SPK) audits, and Competition Authority investigations. These audits are generally supported by the threat of legal sanctions and penalties.

3. Types of Audits According to Timing

The timing of the audit creates a critical distinction as to whether the audit is corrective or preventive.

  • Proactive Auditing: This type of audit is conducted before a transaction actually takes place or at the very beginning of the process. For example, ensuring an expenditure goes through the budget approval process before it is made is a preventative audit. It helps prevent errors before they occur.
  • Simultaneous (Current) Audit: This is an audit conducted while the process is ongoing. It involves real-time monitoring of whether the company's daily operations comply with regulations.
  • Reactive Audit: This is an audit conducted after the activities have been completed and the period has closed. Annual independent audits are an example of this type. Reactive audits aim to identify past errors and prevent similar ones from recurring in the future.

4. Types of Audits According to Their Scope

  • Full (General) Audit: This involves a detailed examination of all company units, all financial transactions, and management decisions. It is costly, but it provides a complete snapshot of the company.
  • Limited (Specialized) Audit: This type of audit focuses solely on a specific issue, department, or period. For example, an audit conducted to investigate a suspected corruption allegation, or a review of only a company's inventory management, are examples of a limited audit.

The Complementary Role of Different Types of Audits

An effective audit system in joint-stock companies is established not by the mutual exclusion of these types of audits, but by their complementarity. In a company where internal auditing is weak, conducting external audits only at the end of the year leaves the company vulnerable to risks. Or, in a company where operational auditing is not performed, financial auditing only confirms that "the records are kept correctly"; however, it cannot explain why the company is losing money or market share. Therefore, in advanced joint-stock companies, the "three lines of defense" model is applied:

  1. First Line: Operational managers and employees (control of their own processes).
  2. Second Line: Risk management and compliance units (for extra monitoring).
  3. Third Line: Internal audit (independent and objective review).

External oversight is the "final link" built upon these lines, providing security against the outside world.

The Legal Aspects of Audit Types and the Turkish Commercial Code

The Turkish Commercial Code mandates or requires most of these audit types for joint-stock companies. In particular, the Turkish Commercial Code No. 6102 has transformed auditing from a purely financial obligation into a tool that enhances the managerial quality of the company. The diversification of audit types facilitates not only the fulfillment of legal obligations but also allows management to identify its own shortcomings and update its strategy. For a board member, having access to data from different audit types (internal audit report, independent audit opinion, activity analysis) is a major support in fulfilling their role as a "prudent manager.".

In summary, audit types are a spectrum. Companies that utilize this spectrum can survive in highly uncertain global markets. Company management that perceives auditing solely as "someone is controlling us" will never grasp its true value. The right combination of audit types can move a company from chaos to orderly operation.

 Auditing of Joint Stock Companies According to Turkish Commercial Code No. 6102

The Turkish Commercial Code No. 6102 has brought about a fundamental paradigm shift in the law of joint-stock companies. The "auditor" system, implemented under the old law of 1956, generally remained a formal control mechanism and, in practice, became an extension of company management. The new Turkish Commercial Code No. 6102, however, has re-envisioned auditing as the "heart of corporate governance," aligning transparency, accountability, and audit quality with international standards (particularly European Union directives). In this new system, auditing is not merely a compliance tool, but a guarantee of the company's financial health and managerial discipline.

1. The Basic Logic of the Audit System: From “Auditor” to “Independent Audit” The new Turkish Commercial Code (TTK) has largely eliminated the concept of “auditor” in the old law, transferring the audit work to a professional group called “independent auditors.” In the old system, auditors could be individuals elected by the general assembly without requiring any professional certification. With the new regulation, it is stipulated that audit activities can only be carried out by professional audit firms or certified public accountants. This has made it mandatory for audit activities to be carried out in accordance with “capital market standards” and has strengthened the independence of the auditor. The legislator now defines the auditor not as an employee of the general assembly, but as a “guarantor” who acts in the public interest and confirms the accuracy of financial reports.

2. Scope and Subjects of the Audit According to the Turkish Commercial Code (TTK), the audit covers the compliance of the company's financial statements (balance sheet, income statement, footnotes, annual activity report, etc.) with legal regulations and the articles of association. The scope of the audit is not limited only to the accuracy of the accounts; the functioning of the company's financial reporting process, the adequacy of the internal control system, and the consistency of the method followed by the board of directors in preparing the financial statements also fall within the scope of the audit. The auditor is obliged to report whether the annual activity report is consistent with the financial statements and whether there are any elements threatening the company's going concern (financial risk analysis). This gives the auditor the authority and responsibility to conduct a "forward-looking" review. If the company is facing a risk of bankruptcy, the auditor must clearly state this in the report.

3. Audit Report and Legal Implications The final result of the audit process is the "audit report." The auditor can express their opinion in four different ways after conducting their examination: a favorable opinion, a limited favorable opinion, a negative opinion, or a refusal to express an opinion. The Turkish Commercial Code system submits this report to the general assembly for approval. Financial statements prepared without an audit report may be considered "null and void," even if approved by the general assembly. This means that the audit report becomes a "precondition for validity" for general assembly decisions. If a "negative opinion" is given in the audit report, or if an opinion is refrained from, this makes it difficult to discharge the board of directors and may even constitute strong evidence for shareholders to file a compensation lawsuit against the board of directors.

4. Selection and Term of Office of the Auditor Auditors are, as a rule, elected by the general assembly. However, certain limitations have been imposed to ensure the independence of the auditor. For example, periodic rotation practices are foreseen because the same auditor auditing the same company for many years (due to auditor fatigue and informality) can compromise independence. The auditor's term of office ends at the end of the auditing period, but if the election is not held by the general assembly in a timely manner, the auditor's term of office continues until a new auditor is appointed. Removing an auditor from office by a decision of the general assembly is quite difficult; unless there is a justifiable reason, the general assembly's removal of the auditor gives rise to the auditor's right to compensation and damages the company's market reputation.

5. Auditor's Responsibilities and Legal Status The Turkish Commercial Code (TTK) imposes significant responsibilities on the auditor. The auditor is obligated to demonstrate "professional diligence and care" in performing their duties. If the auditor fails to detect serious errors or fraud in the company's financial statements during the audit, and this results in damage to the company or mislead shareholders/third parties, the auditor is liable for personal damages. This liability necessitates that the auditor obtain insurance. The auditor's responsibility extends beyond the date of signing the report to cover all negligence during the audit process. The auditor is also subject to a "confidentiality" obligation; they cannot disclose trade secrets learned during the course of their duties.

6. Differentiation of Audit Requirements in Small and Medium-Sized Enterprises: The Turkish Commercial Code No. 6102 does not design the audit system as an "equal and heavy burden for all companies." The law tiers the audit obligation according to the size of the company (criteria such as total assets, annual sales revenue, and number of employees). While audit obligations are more flexible for small-scale companies (SMEs), "independent audit" is absolutely mandatory for large-scale companies and those of public interest (publicly traded companies, banks, etc.). This distinction aims to both optimize audit costs and prevent companies from being overwhelmed by the audit process.

7. Relationship Between the Board of Directors and the Auditor: In the new system, the relationship between the board of directors and the auditor is an "auditor-audited" relationship. The board of directors is obligated to provide the auditor with all documents, answer their questions, and ensure access to any data they need. Any obstruction of the auditor by the board of directors, misleading them, or concealment of documents is considered a crime under the Turkish Commercial Code ("obstruction of audit"). If the auditor is subjected to direct or indirect pressure from the board of directors, they have the right to report this directly to the general assembly or, if necessary, to the commercial court. This is the most concrete evidence of the powerful position the auditor holds vis-a-vis the management.

8. Stability of the Audit System The audit system introduced by the Turkish Commercial Code No. 6102 has brought "seriousness and trust" to Turkish business life. Now, it is much more difficult to manipulate balance sheets, distribute fictitious profits, or conceal company assets, as these actions must pass through the filter of independent auditing. Auditing should be seen not as a "fear factor" for company management, but as an "opportunity" to catch and correct errors in a timely manner. As long as the company takes its auditor's report seriously, it can manage its risks and achieve long-term stability.

In conclusion, the auditing system introduced by the Turkish Commercial Code No. 6102 is the most important legal foundation enabling joint-stock companies to become reliable actors in the modern economy. The success of this system depends on protecting the independence of the auditor, the cooperation of the board of directors, and the capacity of shareholders to read and question audit reports.

Independent Audit

Independent auditing is the pinnacle of the auditing system stipulated by the Turkish Commercial Code (TTK). It is the process of having a company's financial statements, activity reports, and other financial data examined by professional auditors from outside the company who have proven professional competence and have no ties to the company's management, control, or capital structure. Independent auditing is the most important legal and technical safeguard that guarantees the accuracy and reliability of the financial data disclosed to the public by joint-stock companies, preventing "loss of trust" in business life.

1. The Fundamental Philosophy of Independent Auditing: “Providing Assurance” The primary purpose of independent auditing is to provide shareholders and third parties (credit institutions, suppliers, government, potential investors) with “reasonable assurance” that the financial statements presented by the company accurately reflect the truth. The auditor does not declare that the financial statements are “accurate,” but rather expresses an opinion that the financial statements are “free from error or fraud.” This distinction is legal; because the auditor cannot audit all of the company's transactions individually (a sampling method is used). Therefore, “reasonable assurance” is based on the assumption that the audit conducted by the auditor within the framework of professional standards is sufficient to find errors. This assurance is a bridge that eliminates the information asymmetry (information inequality) between the company and its shareholders.

2. Principles of Independent Auditor Independence : An audit lacking independence has no legal value. An independent auditor cannot have a family relationship, business partnership, or financial relationship with the company's board members. The auditor's independence is compromised if the ratio of their fees to their total income exceeds a certain level, or if they provide direct consulting services in the company's financial transactions. The Turkish Commercial Code and related professional regulations provide a "conceptual framework" for the protection of independence. In performing their duties, the auditor is accountable only to their own conscience and professional principles; the general assembly or board of directors cannot instruct the auditor to "report a specific opinion." If the auditor's impartiality is in any way called into question, this alone is sufficient grounds for the invalidity of that audit report.

3. Independent Audit Process: Planning, Implementation and Reporting The independent audit process is conducted with the rigor of project management:

  • Planning: This is the stage where the auditor gets to know the company, identifies industry risks, and defines the scope of the audit (which areas to focus on).
  • Implementation: This stage involves reviewing accounting records, participating in inventory counts, confirming information with third parties (bank reconciliations, letters of debt and receivables), and conducting control tests. Here, the auditor "tests" whether the company's internal control systems are functioning properly.
  • Reporting: This is when the auditor announces their findings in an "Independent Audit Report." The report, along with the auditor's opinion (positive, limited positive, negative, or no opinion) and justification, becomes an integral part of the company's financial statements.

4. Types of Auditor's Opinions and Their Legal Consequences

  • Positive Opinion: This is the belief that the financial statements have been prepared in all material respects in accordance with the applicable financial reporting framework (IFRS/BOBİ FRS).
  • Limited Favorable Opinion: This is given when a specific area in the financial statements is found to be in violation of regulations, but this violation does not extend to the entire statement.
  • Adverse Opinion: This occurs when the financial statements do not accurately reflect the company's financial position, discrepancies are widespread, and the statements are unreliable. This is a serious warning sign for the company.
  • Refusal to Express an Opinion: This is given when the auditor cannot find sufficient evidence or when the company obstructs the audit. This is a type of "warning." A negative opinion or refusal to express an opinion by the independent auditor can halt the discharge process at the company's general assembly, lead to a breach of loan agreements (default), and draw the attention of state regulatory authorities to the company.

5. The Going Concern Principle of Independent Auditing: One of the most important responsibilities of independent auditing is to assess whether the company can continue its operations within the next 12 months. If the company is insolvent or lacks sufficient cash flow to continue operations, the auditor must clearly highlight this in their report. This view regarding the "going concern" principle acts as an "early warning system," allowing creditors and shareholders to take precautions before the company enters bankruptcy proceedings.

6. Audit Committee and Communication Independent auditing is not merely a report-writing process; it requires continuous dialogue between the board of directors and the audit committee. The company's audit committee communicates the independent auditor's findings to the board of directors and follows up on the necessary corrections. If the board of directors fails to make the necessary corrections despite the auditor's warnings, the auditor is obligated to report the situation to the general assembly. This is one of the most effective stages of the hierarchical audit mechanism.

7. Cost and Benefit Analysis of Independent Auditing: Independent auditing is a significant cost; audit fees increase depending on the auditor's experience and the complexity of the company. However, this cost is relatively low compared to the "financial credibility" the company gains. An audited company can obtain loans from banks on much more favorable terms, raise capital at a lower cost, and sit at the negotiating table with a stronger position in partnership talks. In other words, independent auditing is not an expense, but an investment that increases the long-term market value of the company.

8. Global Standards and Turkish Law Independent auditing is not just a local regulation, but also a common language of the global investment world. Independent auditing practices in Turkey are compliant with International Auditing Standards (IAS). This compliance ensures that foreign investors do not hesitate to invest in Turkish joint-stock companies; because when an investor looks at the financial report of a company in Istanbul, they know that it has been audited to the same standards as a company in New York or London.

In conclusion, independent auditing is the mirror of the modern corporation. This mirror allows management to see its own mistakes, while also showing shareholders and the public the true face of the company. A report bearing the signature of an independent auditor is considered a "seal of trust" in the business world.

Special Inspection

In joint-stock companies, the most exceptional, yet the most "tough" and "direct" means of auditing to protect shareholders' rights is private auditing. While independent auditing is a routine and periodic process that checks the compliance of a company's general financial statements with standards, private auditing is a "targeted" intervention mechanism that allows for an in-depth examination of a specific event, period, or suspected transaction of the company. Within the framework of the Turkish Commercial Code (TTK), private auditing is the most effective "legitimate defense" line that minority shareholders can resort to against irregularities committed by the majority or the board of directors managing the company.

1. Legal Nature and Purpose of Special Audits A special audit is a type of audit conducted by independent experts appointed by the general assembly or a court when audits performed by the board of directors are insufficient or do not inspire confidence. Its purpose is to alleviate shareholders' suspicions about company management or, if justified, to reveal these irregularities with concrete evidence and initiate legal proceedings (compensation claims, dismissal, etc.). A special audit does not focus on the company's general financial statements, but rather aims to shed light on a specific area that is "controversial and shrouded in darkness." For example, the acquisition of real estate at a price below market value, covert transactions between board members or their relatives, or the unexplained transfer of the company's cash resources to another company are key subjects of a special audit.

2. Requesting a Special Audit from the General Assembly (Turkish Commercial Code Article 438) The special audit process generally begins at the general assembly. Each shareholder may request at the general assembly that the board of directors clarify specific events through a special audit. In making this request, the shareholder exercises their right to "obtain information and conduct an investigation." The general assembly votes on this request; if accepted, special auditors are appointed. However, in practice, the majority shareholders managing the company may vote "no" to a special audit decision that would reveal the mistakes of the board of directors they themselves appointed. This is where the Turkish Commercial Code introduces the "minority rights" mechanism. If the general assembly rejects the request for a special audit, shareholders representing at least 10% of the capital (5% in publicly traded companies) can apply to the court to request the appointment of a special auditor. This is a legal avenue where the minority can overcome the majority's will to "remain silent and conceal."

3. Requesting a Special Auditor from the Court (Turkish Commercial Code Article 439) When applying to the court, shareholders must prove their "right to request an audit" and "reasonable suspicions that the board of directors has acted improperly." The court appoints a special auditor not only on suspicion but also when convinced of the existence of serious and justifiable reasons. Here, "justifiable reason" is a concrete allegation concerning a transaction by the board of directors that is likely to cause harm to the company. When appointing a special auditor, the court clearly limits the scope, duration, and matters to be audited. The audit process takes place under the supervision of the court; this demonstrates the seriousness of the legal intervention required for a special audit.

4. Powers and Reporting of the Special Auditor Special auditors are independent of company management. They have the authority to examine all company books, documents, cash, bank accounts, and board of directors' decisions. The board of directors cannot prevent the special auditor from performing their duties; if they do, they will incur both legal and criminal liability. The special auditor submits their findings in a report to the court (or the general assembly). This report serves as an "expert report" in legal disputes. If the special audit report confirms irregularities, this report becomes the most important evidence in compensation lawsuits filed against management and in the process of impeaching the board of directors at the general assembly.

5. Cost and Responsibility of Special Audit The special audit process can disrupt the company's overall operations for a period of time and requires the payment of significant fees to expert auditors. The Turkish Commercial Code (TTK) also regulates who will bear this cost. If the special audit definitively establishes that the board of directors is guilty or has committed irregularities, the special audit costs are borne by the company or the (guilty) board of directors. However, in cases where shareholders request a special audit with malicious and unsubstantiated claims, unnecessarily burdening the company, the court may impose the special audit costs on the shareholders who made the request. This is a deterrent measure that closes the door to "unsubstantiated complaints."

6. The Impact of Private Audits on Company Image : A private audit is like a "red card" for company management. A thorough examination of the company by an external private auditor can create the public perception that "things are going badly at the company." However, from a legal perspective, a private audit is not a tool for destruction, but a tool for improving corporate health. A well-managed company does not shy away from a private audit; because if the allegations are found to be unfounded as a result of the private audit process, the board of directors is cleared, and trust among shareholders is renewed. Therefore, a private audit is not only a "punishment" but also a "purification" process that establishes transparency.

7. Differences Between Independent Auditing and Special Auditing. These two types of auditing should not be confused with each other:

  • Independent auditsexamine the "general" state of a company; specialized audits focus on a "specific" event.
  • Independent auditsare, as a rule, "periodic" (once a year); special audits, on the other hand, can take place "whenever needed".
  • Independent auditsprovide assurance on a company's financial reports; specialized audits provide a defense against management's administrative and business misconduct. Independent audits are like a "check-up" for the company, while specialized audits are like "surgical intervention targeting a specific problem" within a particular organ.

Special auditing is the last bastion protecting the democratic legitimacy of a joint-stock company. It is a mechanism that prevents majority shareholders from using the company as if it were their private property, giving the minority the opportunity to transform their "voice into real power." If avenues for special auditing are open in a company and shareholders are not hesitant to use them, the likelihood of that company's management remaining "within the bounds of the law" is very high. Special auditing is the final stage within the "auditing discipline" of joint-stock company law and one of the most refined tools the law has developed against the abuse of power.

Leave a Reply

Call Now Button