ISQM 1
Quality Management for Firms that Perform Audits or Reviews of Financial Statements, or Other Assurance or Related Services Engagements
1Objective and scope
ISQM 1 deals with a firm's responsibility to design, implement and operate a system of quality management (SoQM) for audits and reviews of financial statements and for other assurance and related services engagements. It replaced ISQC 1 and has applied since 15 December 2022 (a firm's system had to be designed and implemented by that date, with the first annual evaluation within a year of it). The shift from ISQC 1 is from a checklist of policies and procedures to a risk-based, scalable system: the firm sets quality objectives, identifies the risks that threaten them, and designs responses to those risks, then monitors and remediates the whole system continuously.
The objective of the firm is to design, implement and operate a system that provides reasonable assurance that (a) the firm and its personnel fulfil their responsibilities under professional standards and legal and regulatory requirements and conduct engagements accordingly, and (b) engagement reports issued by the firm or engagement partners are appropriate in the circumstances. ISQM 1 applies to every firm performing engagements under IAASB standards, whatever its size; ISQM 2 (engagement quality reviews) and ISA 220 (Revised) (quality management at engagement level) sit beneath it and depend on it.
2Key definitions
3Requirements
The eight components
| Component | What it requires |
|---|---|
| Governance and leadership | A culture that puts quality first, leadership that is accountable and demonstrates commitment through actions and behaviour, an organisational structure and resourcing that support quality, and financial and operational priorities that do not undermine it. |
| The firm's risk assessment process | Establish quality objectives, identify and assess quality risks (considering conditions, events and circumstances at the firm), and design and implement responses. This is the engine that drives every other component. |
| Relevant ethical requirements | The firm and its personnel understand and fulfil the IESBA Code (or national equivalent) including independence, and identify and address breaches. |
| Acceptance and continuance | Judgements about whether to accept or continue a client relationship or engagement, informed by the client's integrity and ethical values, the firm's ability to perform (competence, capabilities, time, resources), and whether financial and operational priorities are inappropriately influencing the decision. |
| Engagement performance | Engagement teams understand and fulfil their responsibilities; direction, supervision and review are appropriate; professional judgement and scepticism are exercised; consultation and differences of opinion are handled; and documentation is assembled and retained on time. |
| Resources | Human, technological and intellectual resources (methodologies, tools, guidance) are obtained, developed, used, maintained and allocated in a timely manner, including resources from service providers. |
| Information and communication | An information system that captures and communicates what the SoQM needs, internally and externally, including a transparency report where required by law or regulation or chosen by the firm. |
| Monitoring and remediation | Monitoring activities that provide information about the design, implementation and operation of the SoQM; evaluation of findings to identify deficiencies; root cause analysis; and remedial action that is evaluated for effectiveness. |
Responsibilities and accountability
- The firm assigns ultimate responsibility and accountability for the SoQM to its chief executive officer, managing partner, or managing board of partners.
- Operational responsibility for the SoQM, for compliance with independence requirements, and for the monitoring and remediation process are each assigned to named individuals who have the experience, knowledge, influence, authority and time to discharge them.
- Those individuals report to the person with ultimate responsibility, and the firm holds them accountable through performance evaluation, compensation and promotion decisions.
The risk assessment process
The firm establishes the quality objectives ISQM 1 specifies (plus any additional objectives it needs), then identifies quality risks by obtaining an understanding of the conditions, events, circumstances, actions or inactions that may adversely affect those objectives: the nature of the firm (size, structure, networks, use of technology), its clients and engagements, its personnel, and its financial and operational priorities. It assesses each risk and designs responses that address the assessed risks. Certain responses are mandated: an independence confirmation from all personnel at least annually, a complaints and allegations process, engagement quality reviews for listed entity audits and other engagements the firm identifies, and a policy on how to respond when information suggests a client should not have been accepted.
Monitoring, remediation and annual evaluation
- Monitoring activities are designed in response to the SoQM's own quality risks and include inspections of completed engagements: at least one completed engagement per engagement partner on a cyclical basis, with the cycle set by the firm.
- Findings are evaluated to determine whether deficiencies exist; the firm investigates the root causes of deficiencies and evaluates their severity and pervasiveness before designing remedial actions.
- Where a deficiency indicates a report may be inappropriate or procedures were omitted, the firm takes action (for example, additional work or communication with those charged with governance) as well as fixing the system.
- At least annually the person with ultimate responsibility evaluates the SoQM and concludes whether it provides reasonable assurance that its objectives are being achieved, whether it does so except for identified deficiencies, or whether it does not. That conclusion is documented.
4Documentation and reporting
The firm documents the SoQM sufficiently to support a consistent understanding of it, to demonstrate the design, implementation and operation of its components, and to support the annual evaluation. The documentation must include the quality objectives, quality risks and responses, the basis for the annual conclusion, and the monitoring findings, deficiencies, root causes and remedial actions. It is retained for as long as needed to permit monitoring and any inspection by regulators (a retention period set by law, regulation or the firm's own policy). Engagement-level documentation of quality, including the engagement quality review, is governed by ISA 220 (Revised), ISQM 2 and ISA 230.
Where the firm relies on a network's requirements or services, it must understand them, evaluate whether they are appropriate for its own SoQM, and obtain information from the network about the network's own monitoring of those requirements, including any identified deficiencies and their remediation. Reliance never transfers responsibility: the firm remains accountable for its own system.
5Examinable focus
What KASNEB tests
Expect a question on the eight components and how ISQM 1 differs from ISQC 1 (risk-based, scalable, continuous monitoring, named accountability, annual evaluation). A scenario question typically describes a small firm with a rushed acceptance, an unmonitored partner, or an unresolved ethics breach and asks which quality objectives are threatened and what responses the firm should design. Be able to distinguish a quality risk from a deficiency, and to explain root cause analysis and the three possible annual conclusions. Link firm-level quality (ISQM 1) to engagement-level quality (ISA 220) and the engagement quality review (ISQM 2) in the same answer: examiners reward the connection.