ACCA AAA · Chapter 9
Quality management
Your chapter at a glance. Open any section, or keep the whole map in view.
Firm system and acceptance
Firm-level system risk-based, monitored, remediated
ISQM 1
- Firm designs, implements and operates its SoQM
- System supports quality engagements
ISQM 2
- Requirements for engagement quality reviews (EQRs)
ISA 220 Revised
- Quality management for an individual financial statement audit
Firm’s objective
- Reasonable assurance of compliance with standards and law
- Reasonable assurance that reports are appropriate
A system, not a checklist
- Interrelated objectives, risks and responses must operate
Direction and decisions
- Firm risk assessment process; governance and leadership
- Relevant ethical requirements; acceptance and continuance
Performing engagements
- Engagement performance
- Human, technological and intellectual resources
Learning and communication
- Information and communication
- Monitoring and remediation process
Risk-based and ongoing
- Set quality objectives, identify / assess quality risks
- Design responses; revise when the firm or engagements change
Monitor operation
- Inspect completed files and firm records
- Consider staff feedback, complaints and external findings
Identify deficiencies
- Missing objectives / risks; weak design or implementation
- Responses not operating effectively
Evaluate and investigate
- Assess severity and pervasiveness; establish root causes
Remediate and test
- Address causes, not only instances; monitor effectiveness
- Match action to resources, workload or leadership cause
Sequence
- Finding → Deficiency → Root cause → Remedial action → Evaluation
Know the client and engagement
- Assess integrity of owners, management and TCWG
- Assess scope, complexity, reporting and timetable
Can the firm perform it?
- Independence and conflicts across firm / network
- Competent staff, time, specialists and other resources
- Eligible EQR reviewer if one is required
Decide and document
- Record significant judgments and approval
- Decline if necessary resources cannot be obtained
Key point
- Potential fees cannot override quality considerations
Engagement quality and oversight
Engagement quality involvement throughout, not at the end
Objective evaluation
- Review significant judgments and conclusions
- Complete on or before the engagement report date
Required for
- Audits of listed entities
- Engagements specified by law or regulation
- Engagements selected by the firm to address quality risks
Risk-based example
- Subjective specialist estimates may warrant an EQR
- An unlisted entity may still require an EQR
Responsibility
- EQR does not transfer responsibility from engagement partner
Eligible and objective
- Outside engagement team; competence, time and authority
- Comply with ethics and applicable independence requirements
- Former partner ordinarily needs two-year cooling-off
Review throughout
- Discuss significant matters; inspect selected documentation
- Challenge scepticism, evidence, consultations and conclusions
For financial statement audits
- Evaluate independence and partner involvement
- Review financial statements and proposed auditor’s report
Completion
- Stand back; report cannot be dated before EQR completion
Overall responsibility under ISA 220
- Manage and achieve engagement quality
- Remain sufficiently involved throughout the audit
Lead and resource
- Ethics, acceptance, staff, direction and supervision
- Consult on difficult matters; resolve differences of opinion
Review and conclude
- Strategy, risks, significant judgments, evidence and report
- Determine before report date that involvement was sufficient
Evaluate a shortfall
- Identify specific failure in resources, supervision or review
- Explain how it affects evidence and audit quality
Potential benefits
- Clarify duties and respond to failures
- Strengthen scepticism, evidence and consistency
Implementation matters
- Update methodology, SoQM, programmes and guidance
- Provide training, consultation and appropriate resources
Monitor adoption
- Communicate changes and check their effective application
Key point
- Understand, implement and monitor revised requirements
- Publication alone does not improve audit quality
Want it on paper? Download the PDF, or print this page.
