SACC: services other than account certification
Services other than certification, independence, self-review risks and the auditor's framework: understand the up-to-date legal framework (articles L821-28 and L821-30 of the French Commercial Code, EU regulation 537/2014), the prohibitions for PIEs and the practical implications.
This topic is part of our service
Business law support in France | Corporate secretarialExpert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.
Quick answer: what is a SACC and which services may a French statutory auditor provide?#
A SACC (service other than the certification of accounts) is any service supplied by a French statutory auditor or their network to an entity whose accounts they certify. Article L821-28 of the Commercial Code lists the prohibited services; the others may be supplied to a public interest entity only once the audit committee has approved them (article L821-30).
SACCs, or services other than the certification of accounts, designate all the services that an auditor (CAC) or its network may or may not provide to an entity subject to a legal audit mandate. This subject is at the heart of audit law in France: it determines where the legitimacy of an ancillary service ends and where the threat to the independence of the auditor begins. Understanding SACCs means understanding why independence is not a formal principle but a concrete operational constraint.
Also find our analysis on the mission of the auditor, the training obligations of CACs and situations where the auditor is obligatory.
Definition of SACCs: what exactly are we talking about?#
A SACC is any service provided by the auditor or by an entity belonging to his professional network, for the benefit of an entity for which this same auditor holds a legal certification mandate, and which does not constitute the certification itself.
The definition is deliberately broad. It also covers:
- the regulated missions provided for by law (report on a capital increase, opinion in the context of a merger-absorption, contribution auditor's report);
- advice, training or assistance services which are not expressly provided for by a text but which are technically possible;
- the tax, legal, social or IT missions that the CAC network could accomplish independently of the CAC itself.
What distinguishes a SACC from an ordinary service is precisely the existence of a certification mandate: it is this mandate which makes the additional service potentially incompatible, and not the nature of the service itself.
Legal basis: the founding texts#
The legal framework of SACCs is based on several complementary texts.
Articles L821-25 to L821-36 of the French Commercial Code, grouped in the subsection on the ethics and independence of statutory auditors, set the independence framework: the auditor must be independent of the person or entity whose accounts they certify. Article L821-27 lists the incompatibilities and article L821-31 forbids the auditor from taking, receiving or keeping, directly or indirectly, any interest in the person or entity for which they carry out an engagement or a service. Independence is assessed both in fact and in appearance: it is not only about avoiding actual conflicts of interest, it is about avoiding any situation that could reasonably be perceived as compromising independence.
Article L821-28 of the French Commercial Code lists the prohibited services, and article L821-30 provides that services other than those prohibited may be supplied to a public interest entity only once they have been approved by the audit committee referred to in article L821-67, which rules after analysing the risks to the auditor's independence and the safeguards applied.
For an entity that is not a public interest entity, paragraph IV of article L821-28 applies: the auditor may not accept or continue an engagement to certify accounts or sustainability information where a self-review risk exists or where their independence is compromised and no appropriate safeguard can be implemented.
Mind the numbering: articles L822-9, L822-11 and L822-11-1, still widely quoted, no longer carry that content. Ordinance no. 2023-1142 of 6 December 2023 renumbered Book VIII of the Commercial Code with effect from 1 January 2024: statutory auditors are governed by articles L821-1 to L821-87, while articles L822-1 to L822-43 now deal with independent third-party bodies and sustainability information auditors.
Regulation (EU) no. 537/2014 of 16 April 2014 is the reference text for public interest entities (PIEs). It lists the non-audit services prohibited for PIEs, with a far more restrictive approach than ordinary French law. It has been directly applicable in every Member State, without transposition, since 17 June 2016.
Old and new numbering: the correspondence table#
Ordinance no. 2023-1142 of 6 December 2023 renumbered Book VIII of the French Commercial Code with effect from 1 January 2024. The references still widely reproduced online no longer point to the right text.
| Reference still frequently quoted | What it actually contains today | Article to quote since 1 January 2024 |
|---|---|---|
| L822-9, presented as the independence principle | An article of the chapter on sustainability information auditors | Ethics and independence: L821-25 to L821-36; incompatibilities: L821-27; prohibition on holding any interest: L821-31 |
| L822-11, presented as the SACC regime | The continuing education duty of sustainability auditors | Prohibited services: L821-28; approval of non-prohibited services by the audit committee: L821-30 |
| L822-11-1, presented as the non-PIE prohibitions | Renumbered | Paragraph IV of article L821-28 |
| H3C (Haut Conseil du Commissariat aux Comptes) | Abolished on 1 January 2024 | H2A, Haute autorité de l'audit |
The principle of independence: the very foundation of the statutory audit#
Independence is not an accessory constraint of the audit mandate: it is its very reason for being. An auditor who is not independent cannot, by definition, certify accounts in a credible manner. His signature only has value because it is that of an independent third party, with no personal interest in the outcome of his mission.
This independence is assessed according to several simultaneous dimensions:
- independence of mind: the CAC forms its judgment autonomously, without allowing itself to be influenced by considerations unrelated to its mission;
- apparent independence: an objective and informed observer must not have reasonable reason to doubt the independence of the CAC;
- independence from the network: the CAC must verify not only its own situation, but also that of the members of its network who would intervene for the same client.
It is precisely because independence is multidimensional that SACCs pose a structural problem: even a technically permissible service can create a threat to independence in appearance, which is enough to make it incompatible with the mandate.
Risk categorization: the four main threats#
The French framework applicable since 1 January 2024 is the ethics standard "Securing the statutory auditor's engagements: implementing the risks and safeguards approach", approved by the order of 28 December 2023 (NOR: JUSC2335250A). Its paragraph 28 lists four families of risk: a risk arising from personal or professional ties, a self-review risk, a financial dependence risk and a conflict of interest risk. The expected method is a case-by-case, documented risks and safeguards analysis, not the mechanical application of a checklist. The sections below set out how these four families play out on SACCs.
The self-review risk#
This is the most direct and the most frequently cited threat. The self-review risk arises when the auditor has to audit or certify items that they prepared, designed, validated or recommended themselves. For example, if the auditor's network designed the inventory impairment policy, the auditor cannot then certify that this same policy was correctly applied without their objectivity being structurally compromised.
This risk explains why bookkeeping, the preparation of financial statements or the design of accounting procedures are prohibited or extremely restricted SACCs.
The conflict of interest risk (advocacy position)#
The risk of advocacy arises when the CAC or its network takes a position in favor of the audited entity in the context of a dispute, a negotiation or a procedure which could have an impact on the accounts. Providing assistance in the event of a tax dispute when you are the CAC of the entity creates an obvious pleading risk: the CAC becomes defender of the interests of its client, while its role is precisely to assess them with a critical distance.
The risk arising from personal or professional ties#
The multiplication of additional services with the same client tends to create human and professional links which, progressively, compromise the critical distance necessary for the audit. This risk of familiarity is insidious because it does not result from any specific event, but from an accumulation of relationships.
The financial dependence risk#
This risk exists when the CAC or its firm derives a significant financial benefit from the non-audit relationship with the audited client. If the share of SACC fees in the firm's total revenue becomes significant, the CAC may unconsciously have an interest in maintaining a commercial relationship rather than issuing an unfavorable opinion on the accounts.
SACC authorized: compatible services#
Not all ancillary services are prohibited. Those that remain possible generally correspond to engagements expressly provided for by law that create no self-review risk.
We can cite in particular:
-
Reports on regulated transactions: the contribution auditor's report on the formation of a company or on a capital increase in kind, the merger auditor's report, the demerger auditor's report. Mind the legal qualification: paragraph III of article L821-2 of the Commercial Code classifies as an "engagement" any engagement entrusted to the auditor by law or regulation, paragraph IV reserving the notion of "service" for work that does not fall within an engagement. These are therefore statutory engagements, not SACCs. Combining them with a certification mandate cannot be presumed risk-free: the contribution auditor is subject to the incompatibilities of article L821-31, to which article L225-8 of the Commercial Code expressly refers, and, outside public interest entities, paragraph IV of article L821-28 prohibits accepting or continuing the certification engagement where a self-review risk exists and no appropriate safeguard can be implemented. The analysis is conducted case by case.
-
One-off technical opinions: in certain circumstances, a technical opinion from the CAC on a specific question may be compatible with its mandate, provided that this opinion does not relate to items that it will be required to certify.
-
Professional training: the training actions that the CAC or its network provides to the entity are not, by nature, incompatible with the mandate, provided that they do not involve operational decision-making.
-
Certification of sustainability information: it too is an "engagement" within the meaning of paragraph III of article L821-2, not a SACC. Its own independence rules are set out in paragraph III of article L821-28, which prohibits the services referred to in points (b), (c) and (e) to (k) of article 5(1) of regulation (EU) no. 537/2014 over the period running from the beginning of the certified period to the publication of the report, and in paragraph II of article L821-30, which requires approval by the audit committee.
SACC prohibited for EIP: the stricter regime of regulation 537/2014#
Public interest entities are defined in paragraph II of article L821-2 of the Commercial Code: credit institutions whose registered office is in France, insurance and reinsurance undertakings, provident institutions and their unions, mutual insurers and their unions, persons and entities whose financial securities are admitted to trading on a regulated market, certain financial holding companies and insurance group companies whose consolidated balance sheet total exceeds a threshold set by decree, and supplementary occupational pension funds and institutions. They are subject to a far more restrictive regime. Article 5 of regulation (EU) no. 537/2014, headed "Prohibition of the provision of non-audit services", sets out a list of services that the auditor or their network cannot provide, whatever the threat analysis shows. In French law, paragraph II of article L821-28 takes over all of those prohibitions without opening the derogation of article 5(3).
Among the SACCs prohibited for public interest entities, the following stand out:
- tax services relating to the preparation of tax forms, payroll tax, customs duties, the identification of public subsidies and tax incentives, assistance with tax inspections carried out by the tax authorities (these last two unless such assistance is required by law), the calculation of direct and indirect tax and deferred tax, and the provision of tax advice;
- bookkeeping services and preparation of financial statements;
- design and implementation services for internal control or risk management procedures connected with the preparation or control of financial information, and the design and implementation of financial information technology systems;
- valuation services, including valuations performed in connection with actuarial services or litigation support services, with no significant-impact condition attached;
- legal services, covering general counsel, negotiating on behalf of the audited entity and acting in an advocacy role in the resolution of litigation;
- human resources services relating to management able to exert significant influence over the preparation of the accounting records or the financial statements, where those services involve searching for or selecting candidates for such positions or checking their references, as well as services relating to the structuring of the organisation design and to cost control;
- promotion, brokerage or subscription services for financial securities;
- IT services having a direct impact on accounting and financial information systems.
That list is a minimum, not a ceiling: article 5(2) expressly allows Member States to prohibit further services where they consider that those services pose a risk to independence, and article 5(4) allows stricter national rules. An auditor who supplies one of these services to a public interest entity whose accounts they certify is in direct breach of the European regulation.
The hard numbers to know for a public interest entity#
| Rule | Threshold or duration | Applicable text |
|---|---|---|
| Cap on fees for non-prohibited SACCs, after three consecutive financial years or more of supply | 70% of the average audit fees paid over the last three financial years, non-audit services required by Union or national law being excluded from the calculation | Article 4(2) of regulation (EU) no. 537/2014 |
| Concentration of one PIE client's fees in the firm's total fees, in each of the last three financial years | Above 15%: the audit committee is informed and the risks and safeguards are analysed jointly with it | Article 4(3) of regulation (EU) no. 537/2014 |
| Cooling-off year before accepting a certification engagement with a PIE | The preceding financial year, where the auditor or a member of their network supplied the services of point (e) of article 5(1) of the regulation | Paragraph I of article L821-28 of the Commercial Code |
| Fine incurred | Up to 250,000 euros for an individual and 1,000,000 euros for a firm, doubled where the breach is repeated within five years | Article L821-71 of the Commercial Code |
The H2A and the CNCC: who supervises what?#
The H2A (Haute autorité de l'audit) is the independent public authority that supervises the statutory audit profession in France. It replaced the H3C (Haut Conseil du Commissariat aux Comptes) on 1 January 2024 under ordinance no. 2023-1142 of 6 December 2023, which carried over its historic remit and extended it to the supervision of sustainability information certification. Any documentation still referring to the H3C describes the law as it stood before 2024.
On SACCs, the H2A can investigate whether ancillary services are compatible with independence and issue opinions and recommendations on good practice. Sanctions are handed down by its sanctions commission, on the scale set by article L821-71 of the Commercial Code.
The CNCC (Compagnie nationale des commissaires aux comptes), the French national institute of statutory auditors, is not a supervisory authority. Under delegation from the H2A it carries out the quality controls of firms that audit no public interest entity and monitors continuing education: the delegation agreements were approved on 6 April 2023, signed on 17 April 2023, ratified by the Minister of Justice on 19 May 2023 and published in the Official Journal on 26 May 2023. It also publishes professional practice standards (NEP), practical guides and SACC analysis grids that are the operational reference for practitioners.
The distinction matters: public oversight and the power to sanction remain with the H2A, for public interest entities and for every other entity alike. The CNCC acts under delegation and has no power to sanction.
Contamination by the network: an area of vigilance#
A point often underestimated: the ban on SACCs does not only apply to the auditor himself, but to his entire professional network. A network includes all entities linked to the CAC by a relationship of control, common ownership, common brand or significant sharing of resources or customers.
This means that if the CAC's sister firm, under the same brand and sharing common partners, provides tax services to a PIE audited by the CAC, the prohibition is imposed, even if the CAC personally did not participate in these services.
Managing SACCs at network level is therefore a discipline in its own right, which requires rigorous internal identification and verification procedures before any mission engagement.
Hayot Expertise Advice: before accepting a side mission for an entity that you are auditing - or before requesting such a service from your CAC - the real question is not "is it useful?", but "is it strictly compatible with the independence framework?". A perfectly legitimate service with an ordinary client can become serious professional misconduct when provided to an audited client. The analysis must be carried out in advance, documented and, for a public interest entity, approved by the audit committee referred to in article L821-67 of the Commercial Code.
Practical implications for businesses#
On the side of the audited entity, the question of SACCs has concrete implications:
When choosing the CAC, it is appropriate to check whether the firm or its network already provides services to the entity, and whether these services would be compatible with a future audit mandate. It is best to anticipate these questions before making the appointment. During the mandate, any new service envisaged with the CAC or its network must be subject to prior verification. The analysis grid published by the CNCC is a reference tool: it makes it possible to identify independence risks and to determine whether sufficient safeguards can reduce them to an acceptable level.
In case of doubt, the auditor can seek the opinion of the CNCC or the H2A before accepting an ancillary engagement. This opinion is not legally binding, but it constitutes an important due diligence which protects the CAC in the event of subsequent dispute.
For companies that change their status, for example a company that goes public and becomes a public interest entity, previously authorized SACCs may become prohibited. A complete review of current services is then necessary.
To find out more about our support in terms of audit and legal advice, consult our page legal advice Paris.
Who approves a non-prohibited SACC in a public interest entity?+
The audit committee referred to in article L821-67 of the French Commercial Code. Paragraph I of article L821-30 makes the supply of services other than those prohibited subject to its approval, that committee ruling after analysing the risks to the auditor's independence and the safeguards the auditor applies. A service that is lawful on paper but not approved remains irregular.
How far does the auditor's network extend?+
Paragraph II of article L821-28 of the Commercial Code extends the prohibition to persons or entities that control the public interest entity or are controlled by it within the meaning of paragraphs I and II of article L233-3, and whose registered office is located in the European Union. That is the legal definition of network contamination: the perimeter to check is not the signing firm alone, but the client's corporate group within the Union.
Is a SACC the same thing as a statutory engagement?+
No, and the law itself draws the line. Paragraph III of article L821-2 of the Commercial Code defines an engagement as the certification of accounts, the certification of sustainability information or any other engagement entrusted to the auditor by law or regulation. Paragraph IV defines a service as the supply of work and statements that do not fall within an engagement. Contribution, merger and demerger audits are therefore statutory engagements, not SACCs.
Who sanctions a prohibited SACC?+
The H2A sanctions commission, the CNCC having no power to sanction. Article L821-71 of the Commercial Code sets the scale: warning, reprimand, a ban on all or part of the engagements for up to three years, removal from one or more registers, withdrawal of honorary status, plus a fine of up to 250,000 euros for an individual and 1,000,000 euros for a firm, doubled where the breach is repeated within five years.
Conclusion#
SACCs are among the most technical and most consequential subjects of audit law. Framing them is not an administrative formality: it guarantees the credibility of the certification report, and therefore the trust that third parties (investors, banks, suppliers, shareholders) place in the certified accounts.
In 2026 the scope was sharply narrowed rather than widened: directive (EU) 2025/794 of 14 April 2025 first postponed waves 2 and 3 by two years, then directive (EU) 2026/470 of 24 February 2026 restricted sustainability reporting to companies whose net turnover exceeds 450,000,000 euros and which average more than 1,000 employees, with transposition due by 19 March 2027. The French State's RSE portal puts the reduction at around 80% of the companies previously concerned. That contraction does not make the SACC question go away: it concentrates it on the groups that remain in scope. Anticipating these issues means protecting both the audited entity and the quality of the auditor's mission.
Frequently asked questions
Can an auditor do accounting for his audited clients?+
Not for public interest entities: regulation (EU) no. 537/2014 expressly prohibits bookkeeping and the preparation of financial statements. For other entities the service is strongly discouraged, because it creates a self-review risk incompatible with the independence required by articles L821-25 to L821-36 of the Commercial Code.
What does an auditor risk who carries out prohibited SACCs?+
They are exposed to sanctions handed down by the H2A sanctions commission, the CNCC having no power to sanction. Article L821-71 of the Commercial Code sets the scale: warning, reprimand, a ban on all or part of the engagements for up to three years, removal from the register, withdrawal of honorary status, plus a fine of up to 250,000 euros for an individual and 1,000,000 euros for a firm, doubled where the breach is repeated within five years. The audit engagement itself may be invalidated. Its professional civil liability can be engaged, and the credibility of its certification reports is seriously damaged.
Do SACCs apply to small businesses or only large ones?+
The rules of independence apply to all entities subject to the statutory auditors, regardless of their size. The prohibitions are, however, reinforced for PIEs (banks, insurance companies, listed companies) under regulation (EU) no. 537/2014, which lists the non-audit services prohibited for those entities, Member States remaining free to prohibit others (article 5(2)).
How to check if a service is compatible with a mandate as an auditor?+
The approach consists of applying the risks and safeguards method of the French ethics standard and reviewing the four families of risk it lists (personal or professional ties, self-review, financial dependence, conflict of interest), consulting the analysis grid published by the CNCC and, for a public interest entity, having the service approved by the audit committee referred to in article L821-67 of the Commercial Code before any commitment. The analysis must be documented in the commissioner's work file.
Does the H3C still exist?+
No. The H2A (Haute autorité de l'audit) replaced it on 1 January 2024 under ordinance no. 2023-1142 of 6 December 2023, taking over its remit and extending it to the supervision of sustainability information certification. The same reform renumbered articles L822-9, L822-11 and L822-11-1 of the Commercial Code: the SACC regime is now set out in articles L821-28 and L821-30, and the scale of sanctions in article L821-71.

Article written by Samuel HAYOT
Chartered Accountant, registered with the Institute of Chartered Accountants. Certified Pennylane trainer.
Regulated French accounting and audit firm based in Paris 8, built to support companies across France with a digital and decision-oriented approach.
Sources
Official and operational sources cited for this page.
This topic is part of our service Business law support in France | Corporate secretarial
Need a quote or personalised advice?
Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.