Quality management has become a central responsibility for modern audit and professional services firms. Audit regulators, clients, investors, and other stakeholders increasingly expect firms to demonstrate not only technical competence but also consistent, documented, and effective quality management practices. The International Auditing and Assurance Standards Board (IAASB) introduced a new quality management framework through ISQM 1, ISQM 2, and the revised ISA 220, replacing the previous ISQC 1 approach. The standards became effective on December 15, 2022.
For audit firms, ISQM compliance is more than creating policies and storing documentation. It requires a proactive system that identifies quality risks, establishes appropriate responses, monitors whether those responses are working, and takes corrective action when deficiencies are identified. This guide explains the key requirements of ISQM 1 and ISQM 2, how firms can prepare for inspections, and how a practical quality management system can support long-term audit quality.
What Is ISQM?
International Standards on Quality Management (ISQM) are designed to strengthen the way audit and assurance firms manage quality. Unlike a traditional checklist-based quality control approach, the new framework focuses on identifying and responding to risks that could prevent the firm from achieving quality objectives.
ISQM 1 applies to firms that perform audits or reviews of financial statements and other assurance or related services engagements under IAASB standards. It requires firms to design, implement, and operate a System of Quality Management (SOQM) that is tailored to their specific circumstances.
The framework encourages firms to consider their size, structure, client portfolio, service lines, resources, technology, and engagement risks. This means that a small audit practice and a large international firm do not necessarily need identical systems. Instead, each firm should develop a quality management system that appropriately responds to its own quality risks.
Understanding ISQM 1
ISQM 1 is the foundation of the firm’s overall quality management system. It replaces ISQC 1 and introduces a more proactive, risk-based approach to quality management. The standard requires firms to establish quality objectives, identify and assess quality risks, design responses, monitor the system, and remediate deficiencies.
A successful ISQM 1 implementation begins with understanding the firm’s environment. Leadership should evaluate the nature of services provided, types of clients served, engagement complexity, personnel capabilities, technology systems, ethical requirements, and external service providers.
The firm can then identify circumstances that may create risks to audit quality. For example, excessive workload, insufficient technical expertise, inadequate supervision, independence concerns, ineffective consultation, poor documentation, or weaknesses in engagement review processes may represent quality risks.
Once risks are identified, appropriate responses should be designed. These responses may include additional training, stronger supervision, mandatory consultations, independence procedures, enhanced review processes, technology controls, or changes to engagement acceptance policies.
The Main Components of an ISQM 1 System
ISQM 1 requires firms to address several important components of quality management. These areas work together rather than operating as separate compliance exercises.
Leadership and Governance
Quality begins with leadership. Partners and senior management should demonstrate that audit quality is more important than commercial considerations. The firm’s leadership should establish clear responsibilities, accountability, and a culture where staff feel comfortable raising quality concerns.
A strong tone at the top helps ensure that policies are followed in practice rather than simply existing in a quality manual. IAASB highlights stronger leadership accountability, governance, and a culture of quality as important features of the modern quality management framework.
Relevant Ethical Requirements
Audit firms must establish processes for compliance with applicable ethical requirements, including independence. These processes should cover identification of threats, evaluation of safeguards, consultation where necessary, and documentation of conclusions.
Independence procedures should be practical and regularly updated. Firms should also ensure that personnel understand their responsibilities and know how to report potential conflicts or ethical issues.
Acceptance and Continuance of Clients
Client acceptance and continuance decisions can significantly affect audit quality. Before accepting or continuing an engagement, firms should consider management integrity, independence requirements, resources, technical competence, engagement risk, and whether the firm can perform the work to the required standard.
Documented acceptance procedures help prevent firms from accepting engagements that exceed their capabilities or create unacceptable quality risks.
Engagement Performance
Engagement teams need appropriate direction, supervision, review, consultation, and documentation. Firms should establish procedures that support consistent engagement execution while allowing professional judgment.
Quality management should also consider whether engagement teams have adequate time, experience, technical knowledge, and access to appropriate specialists.
Resources
ISQM 1 places significant importance on resources. Firms need competent personnel, appropriate technology, sufficient time, and relevant intellectual resources to perform quality engagements.
Resource planning should therefore form part of quality management. A firm that repeatedly assigns complex engagements to inexperienced teams without adequate supervision may face significant quality risks.
Information and Communication
Quality-related information must reach the people responsible for making decisions. Firms should establish channels for communicating policies, changes in standards, inspection findings, consultation outcomes, and identified deficiencies.
Effective communication should operate both from leadership to staff and from engagement teams back to management.
Monitoring and Remediation
Monitoring is one of the most important parts of ISQM 1. Firms need to evaluate whether their SOQM is appropriately designed, implemented, and operating effectively.
Monitoring activities may include engagement file inspections, thematic reviews, internal assessments, interviews, analysis of complaints, and review of recurring deficiencies. When problems are identified, firms should investigate root causes and implement appropriate remedial actions.
ICAEW notes that risk assessment and root-cause analysis are important practical challenges in implementing and maintaining quality management systems.
Understanding ISQM 2
While ISQM 1 focuses on the firm’s overall System of Quality Management, ISQM 2 focuses specifically on Engagement Quality Reviews (EQRs). It establishes requirements relating to the appointment, eligibility, performance, documentation, and responsibilities of the engagement quality reviewer.
An Engagement Quality Review provides an objective evaluation of significant judgments made by the engagement team and the conclusions reached. The reviewer should have appropriate competence, authority, experience, and sufficient time to perform the review effectively.
Firms should establish clear criteria for determining which engagements require an EQR. They should also ensure that the engagement quality reviewer is sufficiently independent from the engagement team and meets applicable eligibility requirements.
The EQR should not become a last-minute compliance exercise. Effective review requires appropriate planning and involvement at the right stages of the engagement.
ISQM 1 vs. ISQM 2
The distinction between the two standards is important. ISQM 1 applies to the firm’s overall quality management system, while ISQM 2 addresses engagement quality reviews for applicable engagements.
ISQM 1 covers areas such as leadership, ethical requirements, client acceptance, engagement performance, resources, information and communication, monitoring, and remediation. ISQM 2 concentrates on the quality review process at engagement level.
Together, they create a framework in which quality is managed at both the firm and individual engagement levels.
How to Prepare for an ISQM Inspection
Inspection readiness should be treated as an ongoing process rather than something a firm starts immediately before a regulatory inspection. Inspectors may examine whether the firm’s policies are properly designed, implemented, documented, and operating effectively.
The first step is to maintain an organized ISQM documentation framework. Firms should be able to demonstrate their quality objectives, identified risks, responses, monitoring activities, deficiencies, root-cause analysis, and remediation.
Engagement files should also demonstrate compliance with applicable policies. Documentation should clearly support important judgments, consultations, reviews, independence assessments, and conclusions.
A mock inspection can be particularly useful. An internal reviewer can select representative files and assess them using an inspection-style approach. The objective is to identify gaps before an external regulator does.
Common ISQM Compliance Challenges
Many firms struggle with ISQM implementation because they treat it as a documentation project rather than a continuous quality management process. Common weaknesses include generic risk assessments, unclear ownership of quality responsibilities, inadequate monitoring, weak root-cause analysis, outdated policies, insufficient documentation, and limited evidence that procedures actually operate in practice.
Another challenge is failing to connect firm-level policies with engagement-level execution. A policy may appear comprehensive, but if engagement files do not demonstrate its application, the firm may still face quality concerns.
Training is also essential. Partners, managers, auditors, and support personnel should understand how ISQM requirements affect their daily responsibilities.
Building a Practical ISQM Compliance Framework
A practical implementation approach can begin with a gap assessment. The firm should compare its existing quality policies and procedures against the requirements of ISQM 1 and ISQM 2.
The next stage is risk identification and assessment. Firms should document quality risks based on their actual circumstances rather than relying entirely on generic templates.
After identifying risks, the firm should develop proportionate responses and assign clear responsibility for each action. Monitoring procedures should then be established to evaluate whether these responses are working.
Finally, the firm should maintain a structured remediation process. When deficiencies are identified, management should determine their severity, investigate root causes, implement corrective measures, and monitor whether those measures resolve the underlying problem.
How HarAik Can Support ISQM Compliance
Professional firms may require specialist support to develop, implement, document, and maintain an effective quality management system. Har Aik Global Associates provides specialized ISQM and Quality Management Support Services for professional firms in Saudi Arabia and beyond. Its service offering includes ISQM support alongside technical accounting, IFRS support, training, digital workflow enablement, and other professional services.
A structured external support model can help firms assess existing systems, identify quality gaps, strengthen documentation, develop risk-based procedures, improve monitoring processes, and prepare for inspection activities. External expertise can also provide an objective perspective when evaluating whether a firm’s quality management framework is genuinely effective.
Conclusion
ISQM compliance is not simply about meeting a regulatory requirement. A properly designed System of Quality Management can strengthen audit quality, improve accountability, enhance consistency, and help firms identify problems before they become serious deficiencies.
ISQM 1 provides the foundation for firm-wide quality management, while ISQM 2 strengthens the Engagement Quality Review process. Together with effective leadership, ethical compliance, risk assessment, monitoring, remediation, documentation, and continuous improvement, they provide a modern framework for managing audit quality.
For firms operating in Saudi Arabia and the wider GCC, maintaining inspection readiness and demonstrating effective quality management can also strengthen professional credibility and client confidence. The most effective approach is to treat ISQM as an ongoing business process embedded into the firm’s culture and daily operations rather than as a one-time compliance project.