Skip to content

Advanced Audit and Assurance (International) · Other current issues

Audit Quality and Quality Management (ISQM 1) for ACCA AAA

Updated 11 October 2026 · Fact-checked

Audit quality is the likelihood that an audit gives a reliable opinion, delivered by competent, ethical, sceptical people following proper procedures. ISQM 1 requires a firm to design, implement and operate a risk-based quality management system. ISQM 2 requires an engagement quality review for specified engagements. You answer by linking causes, findings and responses.

Understand Audit Quality and Quality Management (ISQM 1)

Audit quality is not one measure. It comes from many things working together: the firm's culture, the people on the team, the audit process, the reliability of reports and how well the firm interacts with stakeholders. If one weakens, quality falls.

Regulators inspect audit files and the firm's systems. Typical inspection findings are weak challenge of management estimates, too little evidence for revenue, poor group audit oversight, thin documentation, inadequate scepticism and weak review. Findings are symptoms. Your job in the exam is to find the cause, such as time pressure, poor supervision or inexperienced staff.

ISQM 1 replaced ISQC 1. The old standard was a set of required policies and procedures. ISQM 1 is a risk-based approach. The firm sets quality objectives, identifies and assesses quality risks that could stop those objectives being met, then designs responses to address them. This is meant to be proactive, scalable and tailored to the firm.

The system has eight components: governance and leadership; relevant ethical requirements; acceptance and continuance of client relationships and engagements; engagement performance; resources; information and communication; the firm's risk assessment process; and the monitoring and remediation process. Resources include technological, intellectual and human resources. The standard also sets specified responses, which include engagement quality reviews.

The firm must assign ultimate responsibility and accountability for the system to an individual (or individuals). That person must evaluate the system and conclude on it, as at a specified date, at least annually. There are three possible conclusions: the system provides reasonable assurance that its objectives are achieved; it does so except for certain matters identified; or it does not provide reasonable assurance.

ISQM 1 requires an engagement quality review (EQR) for audits of financial statements of listed entities, for engagements where law or regulation requires one, and for engagements where the firm judges an EQR is an appropriate response to an assessed quality risk. ISQM 2 deals with the appointment and eligibility of the reviewer, how the review is performed and how it is documented. A reviewer who is not on the team objectively evaluates the significant judgements made and the conclusions reached. ISA 220 (Revised) deals with the engagement partner's responsibility for quality on each audit.

Key rules to remember

ISQM 1 risk-based cycle
Quality objectives → Quality risks → Responses → Monitoring and remediation
Use this chain to structure any ISQM 1 answer. Each risk must be linked to a response.
ISQM 1 components
Governance and leadership; relevant ethical requirements; acceptance and continuance; engagement performance; resources; information and communication; the firm's risk assessment process; monitoring and remediation process
Use as a checklist when asked to evaluate or improve a firm's system. Resources cover technological, intellectual and human resources. Specified responses, such as engagement quality reviews, sit within the system.
Annual evaluation
Firm evaluates the system as at a specified date, at least annually, and concludes in one of three ways: (1) reasonable assurance that objectives are achieved; (2) reasonable assurance except for matters identified; (3) no reasonable assurance
The evaluation and conclusion are made by the individual(s) the firm has assigned ultimate responsibility and accountability for the system.
EQR trigger (ISQM 1)
EQR required for listed entity audits, for engagements where law or regulation requires one, and where the firm judges an EQR is a response to an assessed quality risk
ISQM 2 covers reviewer eligibility, performance and documentation. The reviewer must be objective and not part of the engagement team.
ISQC 1 vs ISQM 1
ISQC 1: prescribed policies. ISQM 1: risk-based, tailored, proactive, with continual monitoring
A very common comparison question.

How to solve Audit Quality and Quality Management (ISQM 1) questions

Use this method for any scenario on audit quality, inspection findings or quality management.

  1. 1Read the requirement and note whether it asks for causes, effects, recommendations or evaluation.
  2. 2Pick out facts in the scenario that signal quality problems, such as staff shortages, rushed reviews, a dominant partner or weak files.
  3. 3Link each fact to a quality driver or an ISQM 1 component.
  4. 4State the quality risk: what could go wrong and the impact on the audit opinion.
  5. 5Recommend a specific response, such as training, EQR, consultation, resourcing or monitoring.
  6. 6Add ISQM 2 or ISA 220 points where the engagement level is relevant.
  7. 7Close with the effect on audit quality or public interest, and show professional judgement in your wording.

Quickest way: Fact – risk – response

When to use it: Use under time pressure when the question gives a list of weaknesses and asks you to explain or recommend.

  1. Write each weakness as a short bullet from the scenario.
  2. Beside it write the ISQM 1 component it breaks.
  3. Add the risk to audit quality in one clause.
  4. Add one practical response.
  5. Keep to one mark per point and move on.

Common mistakes in Audit Quality and Quality Management (ISQM 1)

  • Saying ISQM 1 is just ISQC 1 renamed.

    Both cover firm-level quality control.

    Fix: State that ISQM 1 is risk-based, with quality objectives, risks and responses, plus an annual evaluation and a stronger focus on monitoring and governance.

  • Listing ISQM 1 components without applying them.

    Students memorise the list.

    Fix: Tie each component to a fact in the scenario and give a specific recommendation.

  • Treating the engagement quality review as a substitute for team supervision.

    Both are review activities.

    Fix: Explain that the EQR is an objective evaluation of significant judgements by someone outside the team. Direction, supervision and review remain the partner's job.

  • Recommending generic fixes like 'improve quality'.

    Time pressure and a lack of precision.

    Fix: Name the action, who does it and what risk it addresses, such as consultation on a complex estimate.

  • Blaming inspection findings only on staff mistakes.

    Failing to look at root causes.

    Fix: Look at firm culture, workload, resourcing, training and incentives that led to the lapses.

  • Ignoring the public interest angle.

    Focus is only on firm risk.

    Fix: Mention that poor quality harms investors and confidence in markets as well as exposing the firm to sanctions and claims.

Worked examples

Example 1

Your firm's regulator inspection found that on several listed audits, challenge of management's estimates was weak and files contained little evidence of partner involvement. Explain how these findings may reflect weaknesses in the firm's quality management and recommend responses.

Show the solution
  1. Link the findings to components: weak challenge suggests a scepticism and culture issue under governance and leadership, and weak partner involvement suggests an engagement performance and resources issue.
  2. Possible root causes: partners with too many engagements, time and fee pressure, inadequate training on estimates, and incentives that reward speed.
  3. Risk: material misstatement in estimates goes undetected and an inappropriate opinion is issued.
  4. Responses: cap partner workloads or add resources; train staff on challenging estimates and professional scepticism; require documentation of partner involvement; use specialists and consultation on complex estimates.
  5. Monitoring: use file inspections to test whether the changes work, and carry out root cause analysis of the findings.

Answer: The findings point to weaknesses in leadership culture and in engagement performance and resources. The firm should address root causes such as workload and training, strengthen partner involvement and documentation, use consultation and specialists, and monitor the effect through inspection and remediation.

Example 2

A mid-tier firm has just moved from ISQC 1 to ISQM 1. Explain the key differences to the firm's partners and how the firm should respond to a quality risk that new audit staff lack experience with group audits.

Show the solution
  1. Difference 1: ISQC 1 prescribed policies and procedures, whereas ISQM 1 requires the firm to set quality objectives, identify and assess quality risks and design responses.
  2. Difference 2: ISQM 1 adds a firm risk assessment process, a stronger emphasis on governance and leadership accountability, and an annual evaluation of the system.
  3. Difference 3: Monitoring and remediation is broader, including root cause analysis of deficiencies.
  4. Apply the quality risk: inexperienced staff on group audits could mean inadequate oversight of components and insufficient evidence.
  5. Responses: assign experienced seniors or managers to group engagements, provide group audit training, and set review and supervision requirements for component work.
  6. Add an EQR where group audits are listed or high risk, and monitor the effectiveness of the response.

Answer: ISQM 1 is risk-based and tailored, with objectives, risks, responses and an annual evaluation, unlike ISQC 1. For the group audit risk, the firm should resource engagements with experienced staff, train and supervise less experienced staff, use an EQR where appropriate and monitor whether the response works.

Exam tips

  • Always structure answers around the risk-based chain: objective, risk, response, monitoring.
  • Use scenario facts to find root causes. Marks go for application, not definitions.
  • Keep ISQM 1 firm-level and ISQM 2 and ISA 220 engagement-level in your answers.
  • Where professional skills marks are available, make clear recommendations and show scepticism about the firm's explanations.
  • Watch for the public interest angle in questions about listed clients and regulators.

Practice questions from Other current issues

Audit Quality and Quality Management (ISQM 1) in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Quality and Quality Management (ISQM 1): frequently asked questions

What is the difference between ISQC 1 and ISQM 1?

ISQC 1 required firms to have prescribed policies and procedures. ISQM 1 requires a risk-based quality management system with objectives, risk assessment and tailored responses. It also adds an annual evaluation and stronger governance accountability.

What are the main drivers of audit quality?

Key drivers include firm culture and leadership, competent and ethical people, a sound audit process, effective supervision and review, and good communication with stakeholders. Weakness in any one can reduce audit quality.

When is an engagement quality review required?

ISQM 1 sets the triggers. An EQR is required for audits of listed entities, for engagements where law or regulation requires one, and for engagements where the firm judges an EQR is an appropriate response to an assessed quality risk. ISQM 2 then covers who can be the reviewer, how the review is performed and how it is documented. The reviewer must be objective and not part of the team.

What are audit quality indicators?

They are measures that give insight into audit quality, such as staff experience and training, partner time on the engagement, workload, inspection results and staff turnover. Use them as evidence, not as proof, because they need judgement to interpret.