Introduction
Independent audit requirements in Turkish capital markets are one of the main legal mechanisms protecting investors, shareholders, creditors and market confidence. Public companies, listed companies, investment institutions, collective investment schemes and other capital market participants prepare financial statements that directly affect investor decisions. If those financial statements are unreliable, incomplete or misleading, capital markets cannot function transparently.
In Turkey, independent audit in capital markets is regulated through a combined framework consisting of Capital Markets Law No. 6362, the regulations and communiqués of the Capital Markets Board of Türkiye, known as the CMB or SPK, Turkish financial reporting standards, Turkish auditing standards, Public Oversight Accounting and Auditing Standards Authority regulations, and public disclosure obligations through the Public Disclosure Platform, known as KAP.
The SPK explains that, within the public disclosure principle of capital markets, providing relevant and reliable information to stakeholders is of great importance. Independent audit plays an active role in ensuring that the public is informed accurately and honestly through relevant and reliable information. The SPK identifies Serial X, No. 22 Communiqué on Independent Audit Standards in Capital Markets as the regulation setting out the principles, procedures and rules for independent audit activity, audit firms and independent auditors in the capital markets.
Independent audit should not be viewed as a routine accounting formality. It is a legal assurance mechanism. The independent auditor reviews whether financial statements and other financial information comply with the applicable reporting framework and whether they fairly reflect the entity’s financial position. For listed companies, a defective audit process may affect share prices, public offerings, debt securities, mergers, dividend decisions and investor claims.
Legal Framework of Independent Audit in Turkish Capital Markets
The independent audit framework in Turkish capital markets is based primarily on Serial X, No. 22 Communiqué on Independent Audit Standards in Capital Markets, which was published in the Official Gazette on 12 June 2006 under No. 26196. The SPK’s legislation system lists this communiqué under the capital market institutions section concerning independent audit, rating and valuation institutions.
The framework is also connected to the Communiqué on Principles of Financial Reporting in Capital Markets II-14.1, published on 13 June 2013, which is listed by the CMB among its core capital market communiqués. Article 21 of the English version of the financial reporting communiqué states that independent audit of financial reports prepared under the communiqué is governed by the Board’s regulations on independent audit. It also provides that, for consolidated financial reports, the parent company is responsible for providing the information and documents required by the independent audit firm.
The SPK has also explained that Turkey’s independent audit system was affected by the establishment of the Public Oversight Accounting and Auditing Standards Authority under Decree Law No. 660, and that CMB regulations were adapted to align with Capital Markets Law No. 6362 and KGK regulations. The SPK’s 2014 announcement also stated that Turkish Auditing Standards published by KGK became central to the audit framework.
Therefore, a capital market audit in Turkey should be analyzed through three layers: CMB capital market rules, KGK/Turkish Auditing Standards, and the specific disclosure and reporting duties of the audited entity.
What Is Independent Audit?
In capital market practice, independent audit means the examination of annual financial statements and other financial information of an entity, through audit techniques required under generally accepted independent auditing standards, in order to obtain sufficient and appropriate audit evidence and provide reasonable assurance on whether the information complies with the applicable criteria.
The SPK defines independent audit as auditing and evaluating annual financial statements and other financial information through books, records and documents, by applying the required independent audit techniques in order to obtain sufficient and appropriate independent audit evidence providing reasonable assurance as to whether the statements and information comply with the applicable criteria, such as financial reporting standards determined or accepted by the CMB for public company financial statements.
This definition shows that independent audit is not a guarantee that the company will be profitable, that its shares will increase in value, or that no future financial problem will occur. It provides reasonable assurance on the financial statements within the audit framework. Reasonable assurance is high assurance, but it is not absolute certainty.
Limited Independent Audit or Review
Turkish capital market law also recognizes limited independent audit, commonly referred to as limited review. The SPK explains that limited independent audit is the review of interim financial statements to determine whether they are prepared in accordance with the financial reporting standards published by the CMB, mainly by using inquiry and analytical review techniques, and reporting the results.
Limited review is narrower than a full annual independent audit. It is generally used for interim financial statements. Because interim reports may influence investor expectations and market prices, they still require independent review for many capital market entities. However, investors should understand that limited review does not provide the same level of assurance as a full audit.
For listed companies, limited review is particularly relevant because investors often trade based on quarterly or semi-annual performance. A company may announce profit growth, debt changes, cash flow deterioration or impairment in interim reports. If such information is not reviewed properly, market decisions may be distorted.
Special Independent Audit
A third category is special independent audit. The SPK defines special independent audit as the independent audit of financial statements prepared as of a specific date by enterprises applying to the CMB for public offering of capital market instruments or by enterprises involved in merger, demerger, transfer or liquidation, in accordance with the principles required by independent audit.
Special independent audit is especially important in transactions that may materially affect investors. Examples include IPOs, debt securities offerings, mergers, demergers, transfers, liquidation processes and corporate restructurings. In these situations, investors and regulators need reliable financial information as of a particular transaction date.
For example, in a public offering, audited financial statements support the prospectus. In a merger, audited financial statements may affect exchange ratios. In a demerger, financial information helps investors understand what assets and liabilities are being transferred. Therefore, special independent audit is not an administrative burden; it is a transaction integrity requirement.
Entities Subject to Independent Audit
The SPK’s independent audit guide states that, under capital market legislation, entities subject to independent audit, limited review and special independent audit are regulated by Serial X, No. 22. It explains that enterprises determined under Article 397/4 of the Turkish Commercial Code, investment funds, housing finance funds and asset finance funds must have their annual financial reports independently audited.
The same SPK guidance states that, subject to special provisions in CMB financial reporting regulations, six-month interim financial statements of certain entities are subject to limited independent audit. These include investment institutions, collective investment institutions other than investment funds, mortgage finance institutions, and joint-stock companies whose capital market instruments are traded on an exchange or other organized market.
This means that independent audit obligations differ depending on the legal status and market position of the entity. A listed company, an investment firm, a portfolio management company, a fund, a mortgage finance company or an issuer of capital market instruments may all face different audit and review duties. The first step in any compliance analysis is therefore to identify the entity category.
Listed Companies and Audit Obligations
Listed companies are at the center of capital market audit obligations. The SPK states that companies whose shares are traded on the exchange must prepare and submit financial statements and reports that will be publicly disclosed or requested by the Board in a timely, complete and accurate manner, in accordance with Turkish Accounting Standards and CMB rules on form and content.
The SPK further states that such listed companies must have financial statements and reports determined by the CMB audited or reviewed by independent audit firms included in the CMB list, within the framework of Turkish Auditing Standards, regarding whether the information fairly and accurately reflects the truth.
This obligation is essential for investor protection. Listed company financial statements are used to evaluate profitability, debt, cash flow, asset value, equity, dividend capacity and growth. If these statements are unreliable, the market price may be distorted. Independent audit therefore supports both public disclosure and fair market pricing.
Audit of Board of Directors’ Reports
Independent audit also interacts with the annual and interim reports of the board of directors. Article 21 of the CMB financial reporting communiqué provides that independent audit of annual and interim board of directors’ reports covers whether the financial data and information in those reports are consistent with the audited financial statements and whether they reflect the truth.
This is important because investors do not read only balance sheets and income statements. They also read board reports, management discussions, operational explanations and risk descriptions. If the board report tells a positive story inconsistent with the audited financial statements, the public may be misled.
Directors should therefore ensure that board reports are not drafted as promotional texts. They must be consistent with audited financial data. The audit process helps test that consistency.
Independent Audit Firms Authorized in Capital Markets
Not every audit firm may audit capital market entities. The SPK maintains a section for independent audit institutions and provides a guide for audit firms operating in capital markets. The SPK’s independent audit institutions page includes guidance, application process information, a list of institutions authorized for independent audit in capital markets, notification obligations and information systems audit-related materials.
The SPK guide states that audit firms wishing to operate in capital markets must satisfy conditions set out in Serial X, No. 22. These include KGK authorization, sufficient organization, premises, technical equipment, documents and records to conduct capital market audits, a quality control assurance committee working under at least one responsible partner chief auditor, and mandatory professional liability insurance subject to minimum requirements.
This authorization requirement protects investors because capital market audits require specialized knowledge. Public companies, listed securities, capital market instruments, financial reporting rules and investor disclosure obligations are more complex than ordinary private company accounting.
Requirements for Auditors and Responsible Partner Chief Auditors
The SPK guide also explains that managers and independent auditors working in capital market audit firms must satisfy specific conditions. It refers to KGK authorization for independent auditors to conduct capital market audits and to the conditions set out in Serial X, No. 22.
Responsible partner chief auditors are particularly important. They carry responsibility for audit quality, supervision and reporting. If an audit report is defective, working papers are insufficient or audit evidence is inadequate, the audit firm and responsible persons may face CMB scrutiny.
The SPK’s older quality control findings show the practical importance of these requirements. In its 2008–2010 independent audit quality control study, the CMB identified issues such as audit firms not satisfying establishment conditions and responsible partner chief auditors lacking the required experience in audits of capital market institutions and public companies.
Auditor Independence
Independence is the foundation of independent audit. If an auditor is economically, personally or professionally dependent on the audited company, the audit cannot provide credible assurance. Independence includes both independence in fact and appearance of independence.
Although the user-facing SPK guide does not set out every independence rule in detail, it makes clear that capital market independent audit activity is regulated through specific standards and that audit firms and auditors must satisfy regulatory conditions. In practice, independence issues may arise where the auditor provides prohibited non-audit services, has financial interests in the audited company, has close management relationships, has excessive fee dependence or lacks professional skepticism.
Public companies should avoid treating the independent auditor as a consultant hired to approve management’s preferred presentation. The auditor must challenge management where necessary. Audit committees and boards should also monitor auditor independence.
Audit Firm Notification Obligations
Independent audit firms operating in capital markets have notification duties toward the CMB. The SPK states that, under Article 27 of the relevant part of Serial X, No. 22, independent audit firms must notify the CMB within six business days of changes regarding their articles of association, headquarters including branches, partners, managers and independent auditors, audit team specified in independent audit agreements, legal links with foreign audit firms, and independent audit agreements.
The SPK also states that summaries of quality control reports prepared by the quality control assurance committee for relevant financial reporting periods must be submitted to the Board by the end of August each year.
These obligations support CMB supervision. The Board needs current information on who audits capital market entities, which audit teams are assigned, whether the audit firm’s structure has changed and whether quality control systems are functioning.
Disclosure of Financial Statements and Audit Reports
Independent audit is connected to public disclosure. Listed companies must publicly disclose financial statements, independent audit reports and annual reports under the applicable CMB framework. The SPK’s listed company obligations page expressly includes a section titled “Financial Statement, Independent Audit Report and Annual Report Disclosure Obligation.” It states that listed companies must prepare and submit the relevant reports in a timely, complete and accurate way and obtain independent audit reports from CMB-listed audit firms where required.
In practice, these disclosures are made through KAP. Investors use KAP to access financial statements, audit reports, board reports and material event disclosures. An audit report hidden from investors would not fulfill the function of public assurance.
Disclosure timing matters. A delayed audit report may create uncertainty in the market. A modified audit opinion may significantly affect investor decisions. Companies should plan reporting calendars carefully and coordinate with auditors early.
Types of Audit Opinions
Independent audit reports may contain different types of opinions, such as unqualified opinion, qualified opinion, adverse opinion or disclaimer of opinion. Although the detailed terminology is based on Turkish Auditing Standards, the legal importance in capital markets is clear: the audit opinion affects investor confidence.
An unqualified opinion generally indicates that the financial statements are fairly presented in accordance with the applicable framework. A qualified opinion indicates a specific issue that is material but not pervasive. An adverse opinion indicates serious misstatement. A disclaimer indicates that the auditor could not obtain sufficient appropriate audit evidence.
For investors, the audit opinion should be read carefully. The notes, key audit matters, emphasis of matter paragraphs, going concern explanations and qualifications may reveal major risks. A company with repeated qualified opinions, going concern warnings or audit evidence limitations may carry higher investment risk.
Audit Committees and Board Responsibility
Independent audit does not remove the responsibility of the board of directors. The company’s management prepares financial statements. The board approves and oversees the reporting process. The auditor examines the financial statements and issues an opinion. These roles are separate.
The parent company’s responsibility to provide information and documents needed for consolidated audit is expressly stated in Article 21 of the CMB financial reporting communiqué. This means that management cannot frustrate the audit process by withholding information.
Audit committees play an important role in listed company governance. They should monitor financial reporting, auditor independence, internal control, risk management and audit findings. A board that ignores audit warnings may face liability if investors are later harmed by misleading financial reports.
Independent Audit and Prospectus Liability
Independent audit is also important in public offerings. Prospectuses often include audited financial statements. Investors rely heavily on these statements when deciding whether to buy shares, bonds or other capital market instruments.
If audited financial statements included in a prospectus are false, misleading or incomplete, liability may arise not only for the issuer and signatories but also for audit firms responsible for reports included in or forming the basis of public disclosure documents. The CMB financial reporting and disclosure framework recognizes that independent audit reports may be part of the investor information system, and Article 21 connects audit to CMB independent audit regulations.
In practice, public offering due diligence should therefore include close coordination with the auditor. Any unresolved audit issue, accounting estimate, going concern risk, related-party transaction or contingent liability may become a prospectus liability issue.
Independent Audit in Mergers, Demergers and Special Transactions
Special independent audit is particularly relevant for mergers, demergers, transfers and liquidation. The SPK defines special independent audit to include financial statements prepared as of any date for enterprises applying to the CMB for public offering or involved in merger, demerger, transfer or liquidation.
This matters because transaction values, exchange ratios and shareholder rights may depend on financial statements. A merger based on unreliable financials may harm shareholders. A demerger based on misstated liabilities may distort the allocation of value. A liquidation based on inaccurate statements may harm creditors and investors.
Companies planning special transactions should therefore involve auditors early. Waiting until the transaction is almost complete may delay CMB applications and create disclosure problems.
Information Systems Independent Audit
Capital market audit requirements are not limited to financial statements. Information systems have become essential to securities markets, investment institutions, portfolio management, custody, crypto services and public disclosure.
The CMB’s capital market legislation list includes Communiqué on Independent Audit of Information Systems III-62.2 under the independent auditing, rating and appraisal category. The CMB’s information systems audit communiqué states that the purpose of information systems independent audit is to form an opinion on the compliance, effectiveness and adequacy of the audited institution’s information systems and related internal controls within the framework of information systems management principles.
This is increasingly important because financial reporting depends on reliable data systems. Trading platforms, order records, custody systems, fund valuation systems and accounting systems all rely on information technology. Weak systems may create financial misstatements, cyber risks, unauthorized transactions and investor harm.
CMB Supervision of Audit Institutions
The CMB supervises audit institutions as part of its broader market oversight function. The SPK states that the purpose of Board supervision is to prevent unlawful acts such as negligence, violation and abuse that obstruct the operation of capital markets in a reliable, transparent, efficient, stable, fair and competitive environment and the protection of investor rights. The supervised entities include issuers, public companies, investment institutions, funds, portfolio management companies, portfolio custody companies, independent audit firms, rating agencies, appraisal firms, exchanges, clearing institutions and central depositories.
This broad supervisory authority means that audit failures are not merely private contractual problems between the audited company and the auditor. They may become capital market enforcement issues. If an audit firm fails to comply with standards, issues defective reports or lacks sufficient working papers, the CMB may investigate.
Revocation of Capital Market Audit Authority
The SPK guide states that the authority of an independent audit firm to conduct independent audit in capital markets may be revoked under Capital Markets Law Article 96 and Article 30 of the relevant part of Serial X, No. 22. Grounds include loss of establishment conditions and violations of independent auditing standards. The SPK guide lists examples such as failure to comply with standards on acceptance and change of audit engagements, assigning auditors outside the audit team notified to the CMB, insufficient audit planning and working papers, failure to obtain sufficient audit evidence due to inappropriate audit techniques, and failure to comply with basic reporting principles.
This is a serious sanction. A firm removed from the CMB list may lose its ability to audit capital market entities. For listed companies, choosing an audit firm that later loses authorization may create reporting disruption and reputational harm.
Liability of Independent Audit Firms
Independent audit firms may face legal liability if they fail to conduct audits in accordance with applicable standards and investors suffer damage from misleading financial statements. Liability may arise toward the audited company, investors, regulators or third parties depending on the facts and legal basis.
The risk is especially high where the audit report is included in a prospectus, public offering document, merger file, demerger document, financial report or other public disclosure document. Investors may argue that they relied on audited financial statements when buying or selling securities.
Audit firms should therefore maintain strong working papers, professional skepticism, risk assessment, internal quality control and engagement acceptance procedures. Audit quality is not only a technical issue; it is a legal defense.
Liability of Directors and Management
Directors and managers cannot shift financial reporting responsibility entirely to the auditor. Management prepares the financial statements. The board supervises financial reporting. The independent auditor tests and reports.
If management withholds documents, pressures the auditor, manipulates accounting estimates, conceals related-party transactions or fails to disclose going concern risks, the company and directors may face liability. Article 21 of the CMB financial reporting communiqué specifically places responsibility on the parent company to provide information and documents needed for consolidated audit.
A director should therefore ask whether the auditor received all necessary records, whether significant audit findings were discussed, whether internal controls are sufficient, whether disagreements with the auditor exist and whether financial disclosures are consistent with audit findings.
Investor Protection Function of Independent Audit
Independent audit protects investors by increasing reliability of financial reporting. Investors generally do not have access to company ledgers, invoices, bank records, internal contracts, inventory counts or management estimates. They rely on audited financial statements and audit reports.
An effective audit can detect material misstatements, highlight going concern problems, identify related-party risks, reveal control weaknesses and support accurate public disclosure. However, investors must understand the limits of audit. An audit does not guarantee future performance, does not eliminate fraud risk entirely and does not guarantee that shares or bonds are safe investments.
Investors should read not only the financial statements but also the audit opinion, key audit matters, qualifications, emphasis paragraphs and notes. These sections often contain the most important risk signals.
Common Audit-Related Legal Risks
Common legal risks include late appointment of auditor, failure to appoint a CMB-authorized audit firm, insufficient information provided to the auditor, delayed disclosure of audited financial statements, inconsistency between board reports and audited statements, inadequate audit evidence, undisclosed related-party transactions, failure to address going concern risk, and use of unaudited financial data in public communications.
Another major risk is treating limited review as equivalent to full audit. Interim financial statements subject to limited review provide less assurance than annual audited financial statements. Investors and companies should understand this distinction.
Practical Checklist for Listed Companies
A listed company should follow a strict audit compliance checklist:
Select an audit firm authorized for capital market audits.
Confirm the audit firm’s KGK and CMB status.
Obtain proper corporate approval for auditor selection.
Execute the audit agreement and ensure required CMB notifications are made.
Prepare financial statements under applicable CMB and Turkish Accounting Standards.
Provide the auditor with all documents needed for standalone and consolidated audit.
Ensure board reports are consistent with audited financial statements.
Review audit findings through the audit committee.
Disclose financial statements, audit report and annual report through KAP on time.
Address qualifications, emphasis matters and internal control findings.
Preserve audit-related records and board minutes.
Practical Checklist for Investors
Investors should review:
Whether financial statements are audited or only reviewed.
Which audit firm issued the report.
Whether the audit firm is authorized in capital markets.
The audit opinion type.
Any qualifications, disclaimers or adverse opinions.
Key audit matters.
Going concern warnings.
Related-party transaction notes.
Contingent liabilities.
Subsequent events.
Consistency between financial statements and board reports.
Timeliness of KAP disclosures.
Investors should be cautious where companies repeatedly change auditors, disclose late financial statements, receive modified opinions or provide management explanations inconsistent with audited data.
Conclusion
Independent audit requirements in Turkish capital markets are a fundamental part of investor protection, public disclosure and market confidence. The SPK identifies independent audit as an institution that plays an active role in ensuring that the public is informed accurately and honestly through relevant and reliable information. It is regulated mainly through Serial X, No. 22 Communiqué on Independent Audit Standards in Capital Markets, together with CMB financial reporting regulations and Turkish Auditing Standards.
Listed companies and other capital market entities must prepare financial statements and reports in accordance with CMB rules and have the required reports audited or reviewed by CMB-listed independent audit firms under Turkish Auditing Standards. Article 21 of the CMB financial reporting communiqué confirms that independent audit of financial reports is governed by the Board’s independent audit regulations and that the parent company must provide information and documents needed for consolidated audit.
Independent audit firms must satisfy authorization, organizational, quality control and professional liability requirements, and they must comply with notification obligations toward the CMB. The CMB supervises audit firms and may revoke capital market audit authority in serious cases of non-compliance with audit standards or loss of required conditions.
For public companies, audit compliance is not merely an accounting matter. It affects prospectuses, financial disclosures, KAP announcements, mergers, demergers, dividend decisions, debt securities and investor claims. For directors, independent audit does not remove responsibility for accurate financial reporting. For investors, audit reports are essential documents that must be read carefully before making investment decisions.
In conclusion, independent audit in Turkish capital markets is a legal assurance system supporting transparency, trust and accountability. Any listed company, public company, investment institution, auditor, board member or investor dealing with audit reports, financial reporting disputes, modified audit opinions, public offerings or CMB investigations should obtain professional legal advice where audit compliance or liability risk is present.
Yanıt yok