Skip to content

Advanced Audit and Assurance (International) · Professional and ethical developments

Professional Scepticism, Judgement and Quality Management (ISQM)

Updated 11 October 2026 · Fact-checked

Professional scepticism is a questioning mind and critical assessment of evidence. Judgement is applying knowledge to reach reasoned decisions. Quality management is a firm-level system under ISQM 1, with engagement quality reviews under ISQM 2 and engagement partner duties under ISA 220 (Revised). In exams, link each to the scenario facts.

Understand Professional Skepticism, Judgement and Quality Management (ISQM)

Professional scepticism means you keep a questioning mind, stay alert to conditions that may indicate misstatement, and critically assess audit evidence. It is not distrust of management. It is also not assuming dishonesty. You do not accept explanations just because they sound plausible.

Scepticism can be weakened by bias. Common biases are confirmation bias (favouring evidence that supports your view), anchoring (sticking to last year's conclusion or the client's figure), availability bias (relying on recent or memorable events), overconfidence, and groupthink. Pressures also weaken scepticism: tight deadlines, budget limits, fee dependence, a long relationship with the client, and a dominant client director. Familiarity and self-interest threats from the ethics code often sit behind these.

Professional judgement is applying training, knowledge and experience to decisions where the standards do not give one answer, such as materiality, estimates, going concern and the opinion. Good judgement needs relevant facts, a clear process, consultation where needed, and documentation of the reasoning. Poor judgement often comes from bias or from lack of time and experience.

Quality is managed at two levels. At firm level, ISQM 1 requires the firm to design, implement and operate a system of quality management using a risk-based approach. The firm sets quality objectives, identifies and assesses quality risks, and designs responses. The system has eight components: the risk assessment process, governance and leadership, relevant ethical requirements, acceptance and continuance of client relationships and specific engagements, engagement performance, resources, information and communication, and monitoring and remediation. The firm must evaluate the system as at a specified date at least annually. The individual(s) assigned ultimate responsibility and accountability for the system must then conclude on whether it provides reasonable assurance that its objectives are met. ISQM 1 replaced ISQC 1, which was a policies-and-procedures standard rather than a risk-based system.

At engagement level, ISQM 1 requires the firm to set policies for an engagement quality review in three cases: audits of financial statements of listed entities, engagements where law or regulation requires a review, and engagements for which the firm determines that a review is an appropriate response to its assessed quality risks. That third case comes from the firm's own risk assessment, for example where an engagement has a significant public interest or is high risk. ISQM 2 covers the appointment and eligibility of the reviewer, and the performance and documentation of the review. The reviewer must be objective and have enough competence and authority. ISA 220 (Revised) makes the engagement partner responsible for the overall quality of the engagement, including leadership, ethics and independence, acceptance, resources, direction, supervision and review, consultation, differences of opinion, and monitoring information. It also expects the partner to set the tone, use technology appropriately, and manage the sufficient and appropriate involvement throughout the audit.

Key rules to remember

Professional scepticism
Questioning mind + critical assessment of evidence
Applies throughout the audit, not only at the end. Use it to challenge management's assertions.
ISQM 1 approach
Set quality objectives → identify and assess quality risks → design and implement responses
The system is risk-based. The firm must evaluate it as at a specified date at least annually, and the individual(s) with ultimate responsibility must conclude on it.
ISQM 1 components
Risk assessment process; governance and leadership; relevant ethical requirements; acceptance and continuance; engagement performance; resources; information and communication; monitoring and remediation
These are the eight components. Learn them as a checklist to structure answers on firm-level weaknesses.
Engagement quality review (ISQM 1 and ISQM 2)
Objective review of significant judgements and conclusions before the report is dated
ISQM 1 requires the firm to have policies on engagement quality reviews and their timing. A review is needed for listed entity audits, engagements required by law or regulation, and engagements for which the firm determines a review is an appropriate response to assessed quality risks. ISQM 2 covers reviewer appointment, eligibility, performance and documentation, and the reviewer must notify the engagement partner when the review is complete. The reviewer must not be part of the engagement team.
ISA 220 (Revised) responsibility
Engagement partner = overall responsibility for managing and achieving quality
Includes direction, supervision and review. The partner must be sufficiently and appropriately involved, and must not date the report until a required engagement quality review is complete.

How to solve Professional Skepticism, Judgement and Quality Management (ISQM) questions

Use this method for any scenario question on scepticism, judgement or quality management.

  1. 1Read the requirement and note the verb (identify, explain, evaluate, recommend) and who you are advising.
  2. 2Scan the scenario for clues: deadlines, fee pressure, long tenure, dominant directors, junior staff, unusual explanations, rushed reviews.
  3. 3Name the issue precisely: a lack of scepticism, a named bias, a weak judgement, a firm-level ISQM 1 gap, or an engagement-level ISA 220 or ISQM 2 failure.
  4. 4Explain why it matters, using the scenario fact and the risk to audit quality or the opinion.
  5. 5Link to the right level: firm (ISQM 1), engagement partner (ISA 220 Revised) or reviewer (ISQM 2).
  6. 6Recommend a practical action: more senior review, extra evidence, consultation, team change, an engagement quality review, or remediation.
  7. 7Add professional skills: conclude clearly, be concise, and tailor the tone to the reader.

Quickest way: Clue, risk, level, action

When to use it: Use this when time is short and the scenario lists several quality concerns.

  1. Underline each clue in the scenario.
  2. Write the risk next to each clue (for example: bias, missed misstatement, lack of review).
  3. Tag each as firm, partner or reviewer level.
  4. Give one specific action per tag.
  5. Write the answer in that order, one short paragraph per clue.

Common mistakes in Professional Skepticism, Judgement and Quality Management (ISQM)

  • Defining scepticism as distrust or assuming management is dishonest.

    Students confuse a questioning mind with suspicion.

    Fix: Say it is a questioning mind and critical assessment of evidence, without assuming either honesty or dishonesty.

  • Treating ISQM 1 as the same as ISQC 1.

    The names look similar and older notes still use ISQC 1.

    Fix: State that ISQM 1 is a risk-based system with objectives, risks and responses, plus an annual evaluation. ISQC 1 was based on policies and procedures.

  • Listing biases without applying them.

    Students memorise definitions but not the scenario link.

    Fix: Quote the scenario fact, name the bias, and say what could go wrong in the audit.

  • Giving the engagement quality review role to the engagement partner or team.

    Roles under ISA 220 and ISQM 2 get blurred.

    Fix: The partner is responsible for engagement quality. The reviewer is an objective person outside the engagement team.

  • Recommending only 'more training' or 'more review'.

    Students give generic advice.

    Fix: Give specific actions tied to the weakness, such as a named review, consultation, change of team members or additional evidence.

  • Ignoring monitoring and remediation.

    Students focus on design and forget the follow-up.

    Fix: Say how deficiencies are found, their root causes investigated, and remedial actions taken and evaluated.

Worked examples

Example 1

During the audit of a long-standing client, the audit senior accepts the finance director's explanation for a large increase in receivables without further evidence. The team is close to its budget and the audit has been rolled forward from last year with few changes. Identify the threats to professional scepticism and recommend actions.

Show the solution
  1. Clue 1: acceptance of an explanation without evidence shows a lack of critical assessment, and possibly overreliance on management.
  2. Clue 2: budget pressure may lead the team to cut procedures and accept weaker evidence.
  3. Clue 3: rolling forward last year's audit suggests anchoring and familiarity with a long-standing client.
  4. Risk: receivables may be overstated or fictitious, and misstatement may go undetected.
  5. Actions: obtain independent evidence such as receivable confirmations, post year-end receipts and credit note testing, and review ageing.
  6. Actions: the manager and partner should review the work, and the partner should consider whether the budget allows sufficient work or needs revising.
  7. Actions: reassess risk for this year rather than copying last year's approach, and consider rotating or refreshing team members.

Answer: The senior has not applied professional scepticism. Budget pressure, anchoring and familiarity create the risk. The team should obtain independent evidence, increase supervision and review, and reassess the audit approach for the year.

Example 2

A mid-sized firm audits a listed company. The engagement partner dates the auditor's report before the engagement quality review is complete, because the client wants the results quickly. Explain the quality management issues under ISQM 1, ISQM 2 and ISA 220 (Revised) and recommend actions.

Show the solution
  1. ISQM 1: the firm's policies must require an engagement quality review for a listed entity audit and must address the timing of that review.
  2. ISQM 2: the reviewer must evaluate the significant judgements and conclusions, and must notify the engagement partner when the review is complete. That notification has not happened here.
  3. ISA 220 (Revised): the engagement partner is responsible for overall quality and must not date the report until the engagement quality review is complete.
  4. ISQM 1: the firm should have a response to the quality risk of reports being issued without required reviews, and monitoring should detect breaches.
  5. Risk: significant errors or poor judgements could go unchallenged, and the opinion could be wrong.
  6. Action: withdraw or hold the report if possible, complete the review and resolve its findings, then date the report.
  7. Action: the firm should investigate why the breach happened, identify the root cause, and take remedial action such as system controls preventing report release without review sign-off.
  8. Action: the firm should consider whether its annual evaluation of the system needs to reflect this deficiency.

Answer: Dating the report before the engagement quality review is complete breaches the partner's duty under ISA 220 (Revised) not to date the report until the review is complete, and bypasses the ISQM 2 process in which the reviewer notifies the partner that the review is complete. It also shows a gap in the firm's ISQM 1 system, which should have policies on the review and its timing. The firm should complete the review before reporting and investigate and remedy the root cause.

Exam tips

  • Always tie scepticism and bias to the scenario facts. Generic definitions earn few marks.
  • Keep the levels straight: ISQM 1 is the firm, ISA 220 (Revised) is the engagement partner, ISQM 2 is the engagement quality reviewer.
  • In ethics-style requirements, mention threats such as self-interest and familiarity alongside bias and pressures.
  • Give practical recommendations and show professional skills such as clear conclusions and tailored communication.
  • If a question asks for differences between ISQM 1 and ISQC 1, focus on risk-based design, objectives, governance and annual evaluation.

Practice questions from Professional and ethical developments

Professional Skepticism, Judgement and Quality Management (ISQM): frequently asked questions

What is the difference between ISQM 1 and ISQC 1?

ISQC 1 required firms to establish policies and procedures in set areas. ISQM 1 replaces it with a risk-based system: objectives, risk assessment, responses, monitoring and remediation, and an annual evaluation. It also strengthens governance and leadership.

Who is responsible for quality on an audit engagement?

Under ISA 220 (Revised), the engagement partner has overall responsibility for managing and achieving quality on the engagement. The firm is responsible for the system under ISQM 1. The engagement quality reviewer provides an objective review but does not take over the partner's responsibility.

When is an engagement quality review needed?

Under ISQM 1, a review is required for audits of financial statements of listed entities, for engagements where law or regulation requires one, and for engagements for which the firm determines a review is an appropriate response to its assessed quality risks. Examples are engagements with a significant public interest or high risk. ISQM 2 sets the reviewer's role and requirements.

Which biases should I know for AAA?

Know confirmation bias, anchoring, availability, overconfidence and groupthink. Be ready to explain each in a sentence and show how it would affect an audit judgement in the scenario.