ISA standards contents

ISA standards

ISQM 1

Quality Management for Firms that Perform Audits or Reviews of Financial Statements, or Other Assurance or Related Services Engagements

1Objective and scope

ISQM 1 deals with a firm's responsibility to design, implement and operate a system of quality management (SoQM) for audits and reviews of financial statements and for other assurance and related services engagements. It replaced ISQC 1 and has applied since 15 December 2022 (a firm's system had to be designed and implemented by that date, with the first annual evaluation within a year of it). The shift from ISQC 1 is from a checklist of policies and procedures to a risk-based, scalable system: the firm sets quality objectives, identifies the risks that threaten them, and designs responses to those risks, then monitors and remediates the whole system continuously.

The objective of the firm is to design, implement and operate a system that provides reasonable assurance that (a) the firm and its personnel fulfil their responsibilities under professional standards and legal and regulatory requirements and conduct engagements accordingly, and (b) engagement reports issued by the firm or engagement partners are appropriate in the circumstances. ISQM 1 applies to every firm performing engagements under IAASB standards, whatever its size; ISQM 2 (engagement quality reviews) and ISA 220 (Revised) (quality management at engagement level) sit beneath it and depend on it.

2Key definitions

System of quality management (SoQM)
A system designed, implemented and operated by a firm to provide reasonable assurance that the firm and its personnel fulfil their responsibilities and that engagement reports issued are appropriate. It comprises eight interrelated components.
Quality objectives
The desired outcomes in relation to the components of the SoQM that the firm is to achieve. ISQM 1 sets them for six of the eight components and requires the firm to add its own where needed.
Quality risk
A risk that has a reasonable possibility of occurring and, if it did, of adversely affecting the achievement of one or more quality objectives, individually or in combination with other risks.
Response
Policies (statements of what should or should not be done) or procedures (actions to implement policies) designed and implemented by the firm to address quality risks.
Deficiency
Exists when a quality objective required to achieve the SoQM's objective is not established; a quality risk is not identified or assessed; a response is missing or inadequately designed, implemented or operating; or another aspect of the SoQM (for example the risk assessment process) is missing or not operating.
Engagement quality review
An objective evaluation of the significant judgements made by the engagement team and the conclusions reached, performed by an engagement quality reviewer and completed on or before the date of the report. Its conduct is governed by ISQM 2.
Network and network firm
A larger structure aimed at cooperation that shares profits or costs, common ownership or control, common quality management, a common business strategy, a common brand, or a significant part of professional resources. A firm relying on network requirements or services must still evaluate their appropriateness for its own SoQM.
Service provider
An individual or organisation external to the firm (not the network) that provides a resource the firm uses in its SoQM or in engagements, for example a component auditor outside the network, or an outsourced IT application.

3Requirements

The eight components

ComponentWhat it requires
Governance and leadershipA culture that puts quality first, leadership that is accountable and demonstrates commitment through actions and behaviour, an organisational structure and resourcing that support quality, and financial and operational priorities that do not undermine it.
The firm's risk assessment processEstablish quality objectives, identify and assess quality risks (considering conditions, events and circumstances at the firm), and design and implement responses. This is the engine that drives every other component.
Relevant ethical requirementsThe firm and its personnel understand and fulfil the IESBA Code (or national equivalent) including independence, and identify and address breaches.
Acceptance and continuanceJudgements about whether to accept or continue a client relationship or engagement, informed by the client's integrity and ethical values, the firm's ability to perform (competence, capabilities, time, resources), and whether financial and operational priorities are inappropriately influencing the decision.
Engagement performanceEngagement teams understand and fulfil their responsibilities; direction, supervision and review are appropriate; professional judgement and scepticism are exercised; consultation and differences of opinion are handled; and documentation is assembled and retained on time.
ResourcesHuman, technological and intellectual resources (methodologies, tools, guidance) are obtained, developed, used, maintained and allocated in a timely manner, including resources from service providers.
Information and communicationAn information system that captures and communicates what the SoQM needs, internally and externally, including a transparency report where required by law or regulation or chosen by the firm.
Monitoring and remediationMonitoring activities that provide information about the design, implementation and operation of the SoQM; evaluation of findings to identify deficiencies; root cause analysis; and remedial action that is evaluated for effectiveness.

Responsibilities and accountability

  • The firm assigns ultimate responsibility and accountability for the SoQM to its chief executive officer, managing partner, or managing board of partners.
  • Operational responsibility for the SoQM, for compliance with independence requirements, and for the monitoring and remediation process are each assigned to named individuals who have the experience, knowledge, influence, authority and time to discharge them.
  • Those individuals report to the person with ultimate responsibility, and the firm holds them accountable through performance evaluation, compensation and promotion decisions.

The risk assessment process

The firm establishes the quality objectives ISQM 1 specifies (plus any additional objectives it needs), then identifies quality risks by obtaining an understanding of the conditions, events, circumstances, actions or inactions that may adversely affect those objectives: the nature of the firm (size, structure, networks, use of technology), its clients and engagements, its personnel, and its financial and operational priorities. It assesses each risk and designs responses that address the assessed risks. Certain responses are mandated: an independence confirmation from all personnel at least annually, a complaints and allegations process, engagement quality reviews for listed entity audits and other engagements the firm identifies, and a policy on how to respond when information suggests a client should not have been accepted.

Monitoring, remediation and annual evaluation

  • Monitoring activities are designed in response to the SoQM's own quality risks and include inspections of completed engagements: at least one completed engagement per engagement partner on a cyclical basis, with the cycle set by the firm.
  • Findings are evaluated to determine whether deficiencies exist; the firm investigates the root causes of deficiencies and evaluates their severity and pervasiveness before designing remedial actions.
  • Where a deficiency indicates a report may be inappropriate or procedures were omitted, the firm takes action (for example, additional work or communication with those charged with governance) as well as fixing the system.
  • At least annually the person with ultimate responsibility evaluates the SoQM and concludes whether it provides reasonable assurance that its objectives are being achieved, whether it does so except for identified deficiencies, or whether it does not. That conclusion is documented.

4Documentation and reporting

The firm documents the SoQM sufficiently to support a consistent understanding of it, to demonstrate the design, implementation and operation of its components, and to support the annual evaluation. The documentation must include the quality objectives, quality risks and responses, the basis for the annual conclusion, and the monitoring findings, deficiencies, root causes and remedial actions. It is retained for as long as needed to permit monitoring and any inspection by regulators (a retention period set by law, regulation or the firm's own policy). Engagement-level documentation of quality, including the engagement quality review, is governed by ISA 220 (Revised), ISQM 2 and ISA 230.

Where the firm relies on a network's requirements or services, it must understand them, evaluate whether they are appropriate for its own SoQM, and obtain information from the network about the network's own monitoring of those requirements, including any identified deficiencies and their remediation. Reliance never transfers responsibility: the firm remains accountable for its own system.

5Examinable focus

What KASNEB tests

Expect a question on the eight components and how ISQM 1 differs from ISQC 1 (risk-based, scalable, continuous monitoring, named accountability, annual evaluation). A scenario question typically describes a small firm with a rushed acceptance, an unmonitored partner, or an unresolved ethics breach and asks which quality objectives are threatened and what responses the firm should design. Be able to distinguish a quality risk from a deficiency, and to explain root cause analysis and the three possible annual conclusions. Link firm-level quality (ISQM 1) to engagement-level quality (ISA 220) and the engagement quality review (ISQM 2) in the same answer: examiners reward the connection.