Quality Management
1 Introduction
The IAASB has published three new and revised standards to strengthen and modernise the audit firm’s approach to quality management. These are examinable from September 2022:
ISQM 1 Quality Management for Firms that Perform Audits or Reviews of Financial Statements, or Other Assurance or Related Services Engagements (replaces ISQC 1) deals with a firm’s responsibility to establish a system of quality management to support quality engagements.
A new standard ISQM 2 Engagement Quality Reviews applies to all engagements for which such a review is required in accordance with ISQM1.
ISA 220 (Revised) Quality Management for an Audit of Financial Statements deals with responsibilities for quality management at the engagement level for an audit of financial statements.
2 Quality control (firm-wide)
Under International Standard for Quality Management 1 (ISQM 1), the firm must design, implement and operate a system of quality management to provide it with reasonable assurance that:
The firm and its personnel comply with professional standards and applicable legal and regulatory requirements; and
Reports issued by the firm or engagement partners are appropriate in the circumstances.
Note again the use of the word ‘system’. You will know that under the Code of Ethics for Professional Accountants to avoid self-interest threats firms have to ensure that no one involved in an audit owns shares in the audit client and that fees from any one client must not be too great. However, these safeguards cannot be left up to chance. Audit firms need systems in place that will ensure that ethical codes are not broken and will provide evidence that quality has been maintained. To comply with the self-interest rules just mentioned, the system of quality management might require that each year:
Every member of the audit staff must sign a declaration stating that they do not own client shares.
A partner should review fees and sign a declaration that fee limits have not been exceeded.
ISQM 1 consists of EIGHT components:

Firm’s risk assessment process. The firm must have a risk assessment process to:
Establish quality objectives;
Identify and assess quality risks; and
Design and implement responses to address quality risks.
Governance and leadership. The firm must establish policies and procedure designed to promote an internal culture that recognises that quality is essential in performing engagements.
Relevant ethical requirements (covered earlier in these notes). Throughout the audit engagement, the engagement partner shall remain alert, through observation and making inquiries as necessary, for evidence of non-compliance with relevant ethical requirements by members of the engagement team.
Acceptance and continuance of client relationships and specific engagements. The firm must ensure that decisions are appropriate based on:
the nature and circumstances of the engagement and the integrity and ethical values of the client; and
the firm’s ability to perform the engagement in accordance with professional standards and legal and regulatory requirements.
The financial and operational priorities of the firm must NOT lead to inappropriate decision..
Engagement performance. Overall responsibility for quality rests with the engagement partner who must have sufficient and appropriate involvement throughout the engagement. The nature, timing and extent of direct and supervision of engagement teams and review of their work must be appropriate.
Resources. Three categories of resources are needed to operate the system of quality management and perform engagements: Human | Technological | Intellectual
Information and communication. A firm should have an information system that supports the system of quality. Communication channels need to facilitate the exchange of information within the firm and with external parties including TCWG.
Monitoring and remediation process. Monitoring activities must provide a basis for the identification of deficiencies. Remedial actions to address identified deficiencies need to be responsive to the results of a "root cause analysis".
If there are changes in the nature and circumstances of the firm or the engagements or if the monitoring and remediation process identifies deficiencies, the firm:
Establishes additional quality objectives; and/or
Modifies or adds to the quality risks and responses.
3 Engagement quality review (EQ review)
Public interest audits, such as the audit of listed companies, should undergo an Engagement Quality Review (EQ review). Here, an independent reviewer (normally another partner) will be appointed to perform an objective evaluation of the significant judgments made by the engagement team, and the conclusions reached in formulating the auditor’s report.
An audit firm should set criteria for other engagements, if any, that require an EQ review (eg entities in certain industries identified as high risk). An EQ review includes:
Discussion of significant matters with the engagement partner;
Review of the financial statements and the proposed auditor’s report;
Review of selected audit documentation relating to the significant judgments the engagement team made and the conclusions it reached; and
Evaluation of the conclusions reached in formulating the auditor’s report and consideration of whether the proposed auditor’s report is appropriate.
For audits of listed entities, the EQ review must also consider the following:
The engagement team’s evaluation of the firm’s independence in relation to the audit engagement;
Whether appropriate consultation has taken place on matters involving differences of opinion or other difficult or contentious matters, and the conclusions arising from those consultations; and
Whether audit documentation selected for review reflects the work performed in relation to the significant judgments and supports the conclusions reached.
An EQ review is an example of a pre-issuance ('hot') review - i.e. it is carried out before the auditor’s report is signed. An audit firm may choose to carry out other reviews ('hot' or 'cold') where an EQ review is not required.
4 Quality management (engagement level)
ISA 220, which addresses quality management procedures at the engagement level, presumes that the firm meets the requirements demanded by ISQM 1. At the engagement level, quality management procedures must provide reasonable assurance that:
The audit complies with professional standards and legal requirements
The auditor’s report issued is appropriate in the circumstances.
The engagement partner is responsible for:
Leadership and the overall quality of the audit
Compliance with relevant ethical requirements
Acceptance/continuance of the audit engagement
Assigning a competent and capable engagement team
Engagement performance, including:
Direction, supervision and performance of the audit in accordance with ISAs
Review of audit documentation
Appropriate consultation, where appropriate
Discussion of significant matters with the EQ reviewer, where relevant
Audit documentation (ISA 230) must include:
Ethical issues and how resolved
The engagement partner’s conclusions regarding compliance with independence requirements and the acceptance/continuance of the engagement
The nature and scope of consultations, if any, and the conclusions reached.
Where relevant, the EQ reviewer must document:
That the firm’s EQ review procedures have been performed
That the review has been completed on or before the date of the auditor’s report
That he is not aware of any unresolved matters that would lead him to believe that significant judgements and conclusions are not appropriate.
Remember to check the technical articles section of AAA study resources for this topic.


