This article was originally published in February 2021 when the deadline for implementation of December 2022 no doubt seemed a long way off. We are now a little over a year away, but don't underestimate the huge amount of work required to implement these new standards. Even if you typically buy an off-the-shelf solution, you won't be able to buy the completed product, as the standard requires each firm to consider its own particular circumstances.
If you need help in implementing the changes I can provide services including writing new policies and procedures, running risk identification workshops, providing example risk responses for the identified quality risks, and providing training either remotely, or in person where possible, given any travel restrictions in place. I can do this work for an individual firm or I can assist a network in providing resources to their member firms.
Shortly before Christmas 2020 the IAASB issued the expected suite of new quality management standards for audit and assurance work. The suite comprises International Standards on Quality Management (ISQM) 1 and 2 and a revised version of ISA 220, Quality Management for an Audit of Financial Statements. Whilst these are the international versions of the standards the FRC is already consulting on its proposal to adopt the standards and indeed is strongly encouraging their early adoption. We can therefore expect only minor differences in the requirements and the same effective date, that is for audits of financial statements for periods beginning on or after December 15, 2022.
Before we go any further, it is worth summarising the areas covered by each of these three newly issued standards:
- ISQM 1 – deals with a firm’s responsibilities to design, implement and operate a system of quality management for audits or reviews of financial statements or other assurance or related services engagements.
- ISQM 2 – deals with the appointment and eligibility of the engagement quality reviewer and that reviewer’s responsibilities relating to the performance and documentation of an engagement quality review (EQR previously an EQCR).
- ISA 220 (Revised) – deals with the specific responsibilities of the auditor regarding quality management at the engagement level for an audit of financial statements and the related responsibilities of the engagement partner. It needs to be read in conjunction with relevant ethical requirements.
This might, at first glance, just appear that the old ISQC 1 has been split into two, separating out the requirements for an EQR from the other requirements, and that tweaks have been made to the related ISA. However, the headline scope of the standards hides the fundamental shift in the approach to quality management that the standards embody. The name change, from quality control to quality management, at least hints at the fact that the standards require a more pro-active approach to maintaining quality. Instead of the, arguably, checklist approach of ISQC 1, the new standards require firms to actively consider the risks to quality and to respond to those risks with appropriate procedures. The effective date of December 2022 might suggest there is plenty of time and that nothing needs to be considered in respect of the new standards just yet. This is not the case though, as a lot of work is needed, as you might begin to understand whilst reading the rest of this article. In addition, early adoption of the changes should lead to stronger quality control which should benefit those firms who tackle the topic sooner rather than later.
The most important changes, in terms of overall approach, are within ISQM 1. The standard starts by setting out the elements of a system of quality management as follows:
(a) The firm’s risk assessment process;
(b) Governance and leadership;
(c) Relevant ethical requirements;
(d) Acceptance and continuance of client relationships and specific engagements;
(e) Engagement performance;
(f) Resources;
(g) Information and communication; and
(h) The monitoring and remediation process.
The Factsheet issued with the standard includes a helpful graphical representation of these elements highlighting that they operate in an iterative and integrated manner:
There is great emphasis within the standard on the creation and maintenance of a quality culture and the role of leadership, including quality being embedded in the strategic decisions and actions of the firm.
Once you get past the overall approach, the standard takes a risk-based approach to quality management. The three elements of this are to:
1. Establish quality objectives;
2. Identify and assess quality risks;
3. Design and implement responses (to the risks).
ISQM 1 sets out mandatory quality objectives for most of the elements of the quality system. For some of these elements it also sets out specified (ie mandatory) risk responses. In essence these are the minimum requirements, and a number of the mandatory objectives and responses will look similar to the elements of an existing quality control system.
However, the approach is much more than the existing system, as it requires firms to consider what could go wrong for their particular firm and what responses would sufficiently mitigate the risks of quality shortcomings. It will never be appropriate, under ISQM 1, to have an untailored off-the-shelf quality management system, as policies must be responsive to the firm's own risks.
In order to put in place the new systems for quality management required by ISQM 1 firms will therefore need to consider whether there are any additional quality objectives, not already set out as mandatory within the standard. They will need to assess what risks exist and design an appropriate response to those risks. Consideration of information gathered in previous quality reviews and during any root cause analysis will help to highlight potential risks. For instance, if the firm struggles with having the right staff available at the right time, consideration will be needed as to how to mitigate that risk. If it is not possible to hire more people to fill the gaps, the firm may need to consider reorganising work, resigning from clients they can no longer properly service, using other resources, such as technology solutions if these can free up staff where needed, or training staff up to be able to deal with the areas currently under-resourced. In practice it is likely that a wide range of risk responses will be needed to address the problem, but unlike ISQC 1, which also required adequate resources, ISQM 1 sets out a much more structured approach to managing the risk.
Interestingly, the standard also specifically addresses the impact of networks of accountants. It highlights that the quality management system is the firm’s responsibility, but that the firm must understand the network requirements or services and how these impact its own systems. The firm must also understand the monitoring activities undertaken by the network, including those to determine whether network requirements have been properly implemented. This does not mean there is no role for networks, as the network could still provide a starting point of quality objectives, risks and responses for individual member firms to adapt to their specific situation. After all, it is unlikely that a firm operating in rural England, will have the same risks as one in London, let alone in a very different jurisdiction such as Malawi. But conversely, there will clearly be areas of commonality and there is little point in each firm starting from scratch if a more nuanced starting position can be established by the network.
There is, of course, much more within ISQM 1 given that the standard runs to 73 pages, but the purpose of this article is just to whet your appetite.
We move now to introduce ISQM 2 on Engagement Quality Reviews (EQR). This standard extends the scope of engagements subject to an EQR, so they may be required more often. It also strengthens the eligibility requirements for the person carrying out the review (the EQ reviewer), to ensure independence, competence, sufficient time and seniority for all such reviewers. Finally, it enhances the reviewer’s responsibilities relating to the performance of the review. The focus is on reviewing significant judgments and significant matters and whether the engagement team has exercised appropriate professional scepticism. It also requires the EQ reviewer to “stand-back” to determine whether the performance requirements of the standard have been met.
Finally, ISA 220 has been revised to reflect the new requirements as they apply to an individual audit. The new version focuses on the critically important role of the engagement partner in managing and achieving quality on the audit engagement and reinforces the importance of quality to all team members. it also clarifies that the audit engagement team includes all those who carry out audit work excluding an auditor’s external expert or internal auditors who provide direct assistance (though the latter is not permitted in the UK). This is particularly relevant to those firms who might outsource part of the audit work as it ensures that individuals performing this work are no less a part of the audit team than the manager or engagement partner for example. The standard will require careful consideration of the resource implications of the requirements in order to ensure that engagement partners have the time to fulfil their responsibilities. But this will not be the only impact as all aspects of the new standard will need to be considered and embedded in the audit process.

