Advanced Audit and Assurance (International) · Quality management (firm and engagement level)
Firm Governance, Leadership and Ethical Requirements under ISQM 1
Updated 11 October 2026 · Fact-checked
Under ISQM 1, a firm must set up a quality management system. Governance and leadership set the tone and assign accountability. The firm assesses its quality risks, applies relevant ethical requirements including independence, and only accepts or continues clients when it is competent, ethical and able to meet its duties.
Understand Firm Governance, Leadership and Ethical Requirements
ISQM 1 requires every firm that performs audits or reviews to design, implement and operate a system of quality management (SoQM). The system is risk-based. The firm sets quality objectives, identifies and assesses quality risks that could stop those objectives being met, and designs responses to the risks.
The governance and leadership component sets the culture. Leaders must show commitment to quality through their actions and communications. The firm must assign ultimate responsibility and accountability for the SoQM to the firm's chief executive or managing partner (or managing board of partners). It must also assign operational responsibility for the SoQM, and for specific aspects such as compliance with independence requirements and monitoring and remediation. Those people need the right experience, authority and time. The firm must also plan its organisational structure and resource needs so that quality is not squeezed by commercial pressure.
The firm's risk assessment process is the engine of the system. For each quality objective, the firm identifies risks (what could go wrong), assesses them (likelihood and effect on the objective) and designs responses. Examples: a risk that staff do not understand independence rules is answered by training and annual confirmations. The process must be updated when conditions change, such as a new service line or a change in regulation.
The relevant ethical requirements component covers the IESBA Code and any local rules that apply. The firm must make sure that the firm, its personnel and others subject to independence requirements, such as network firms, comply. Typical responses are an independence policy, a system to identify threats, annual written confirmations, monitoring of financial interests, and rules on rotation and non-assurance services. Threats are self-interest, self-review, advocacy, familiarity and intimidation. Safeguards must reduce a threat to an acceptable level. If they cannot, the firm must eliminate the circumstance or decline or end the engagement.
The acceptance and continuance component is about when a firm takes on or keeps a client. The firm must judge whether it can meet its ethical duties, has the competence, time and resources, and whether the client has integrity and an acceptable reason for the engagement. It looks at client integrity, management's values, any money laundering concerns, conflicts of interest and whether the fee is adequate for quality work. Information found later may mean the firm must reconsider, or even withdraw, subject to legal and ethical duties.
Key rules to remember
- ISQM 1 components
- Firm's risk assessment process; Governance and leadership; Relevant ethical requirements; Acceptance and continuance; Engagement performance; Resources; Information and communication; Monitoring and remediation
- Use these as headings when a question asks about the firm's quality system. The first four are the focus of this topic.
- Risk-based process
- Quality objectives → quality risks → responses
- Every ISQM 1 answer should show this chain. Do not list responses without naming the risk they address.
- Accountability
- Ultimate responsibility: CEO or managing partners. Operational responsibility: assigned to individuals with experience, authority and time
- Operational responsibility covers the SoQM, independence compliance, and monitoring and remediation.
- Threat categories
- Self-interest, self-review, advocacy, familiarity, intimidation
- Name the threat, explain it in the scenario, then give a safeguard.
- Threat response hierarchy
- Eliminate the circumstances; apply safeguards; or decline or end the engagement
- Safeguards must reduce the threat to an acceptable level.
- Acceptance and continuance factors
- Integrity of client + competence, time and resources + ability to comply with ethical requirements + acceptable reason for engagement
- Add conflicts of interest, money laundering risk and fee adequacy where the scenario supports them.
How to solve Firm Governance, Leadership and Ethical Requirements questions
Use this approach for any question on firm-level governance, ethics or acceptance. Tie each point to the facts given.
- 1Read the requirement and identify the component being tested: governance and leadership, risk assessment, ethics and independence, or acceptance and continuance.
- 2Underline the scenario facts that matter, such as a partner under revenue pressure, a long-standing client, a new service line or a fee dependence.
- 3Name the quality risk or ethical threat in each fact. Use the exact label, such as self-interest or familiarity.
- 4Explain why it matters. Say what could go wrong for audit quality or independence.
- 5Give a specific response or safeguard for each point, and say who should do it, such as the engagement quality reviewer or the ethics partner.
- 6State whether the response is enough. If not, conclude that the firm should decline, resign or eliminate the relationship.
- 7Finish with a short professional recommendation. Keep it clear for the reader, such as the board or the managing partner.
Quickest way: Issue, risk, response in one line
When to use it: Use it when time is short or the question is a short list-style requirement worth only a few marks.
- Write a one-line heading for each fact in the scenario.
- Under each, write: risk or threat, then why it matters, then response.
- Use the component names from ISQM 1 as anchors, so the marker sees the framework.
- End with one line that states the overall conclusion, such as accept with safeguards or decline.
Common mistakes in Firm Governance, Leadership and Ethical Requirements
Listing ISQM 1 components without applying them to the scenario.
Students memorise the list and feel it is safe to reproduce.
Fix: Use the components only as headings. Every point must refer to a fact in the case.
Naming a threat but giving no safeguard, or a safeguard with no threat.
Students rush and treat the two parts as separate.
Fix: Write threat, reason, safeguard as a set. Check that the safeguard really reduces that threat.
Suggesting safeguards for every threat, even when they cannot work.
Students assume there is always a fix.
Fix: If the threat is too significant, say so. Conclude that the firm should decline or withdraw.
Treating governance and leadership as just a statement from the top.
The word tone is remembered but not the practical part.
Fix: Mention assigned accountability, resources, performance evaluation and incentives that reward quality, not only revenue.
Ignoring client integrity and management values in acceptance questions.
Students focus on fees and capacity.
Fix: Always cover integrity, competence, resources, ethics and conflicts, and the reason for the engagement.
Confusing firm-level ISQM 1 duties with engagement-level ISA 220 duties.
Both standards deal with quality and the names are similar.
Fix: ISQM 1 is the firm's system. ISA 220 is the engagement partner's responsibility on one audit. Say which level you are discussing.
Worked examples
Example 1
Ridge & Co is a mid-sized audit firm. The managing partner has announced a target of 15% annual revenue growth. Partners' bonuses depend only on fees billed. Several partners say they cut review time on audits to meet client deadlines. Explain the governance and leadership weaknesses and recommend improvements. (8 marks)
Show the solution
- Identify the weakness in tone: the only stated goal is growth. This signals that revenue matters more than quality. Quality risk: staff may cut corners.
- Identify the incentive problem: bonuses based only on fees reward volume and speed, not audit quality. ISQM 1 expects performance evaluation and rewards to show commitment to quality.
- Identify the evidence of poor practice: partners cutting review time means the culture already tolerates reduced quality. This raises the risk of undetected misstatement.
- Identify accountability: the facts do not show that anyone has operational responsibility for quality. The firm should assign ultimate responsibility to the managing partner and operational responsibility to a person with experience, authority and time.
- Recommend: the managing partner should communicate regularly that quality comes first, with real examples.
- Recommend: change the bonus scheme to include audit quality indicators such as inspection results, review compliance and training.
- Recommend: set budgets and timetables that allow adequate review time, and monitor whether reviews are completed before reports are signed.
- Recommend: root cause analysis of the time-cutting, with action on any deficiency found.
Answer: The firm's governance is weak because growth and fee-based bonuses signal that revenue outranks quality, and partners are already reducing review time. The firm should reset the tone from the top, assign clear quality accountability, add quality measures to partner evaluation and rewards, resource engagements realistically, and investigate the cause of reduced reviews.
Example 2
Your firm audits Alpha Ltd. A new prospective client, Delta Ltd, wants an audit. Delta's finance director previously worked for your firm and left only two months ago. He was an audit manager on Alpha. Delta's majority owner is under investigation for suspected tax evasion, and he has asked for a very low fee. Discuss the matters your firm should consider before accepting Delta as a client, and conclude. (10 marks)
Show the solution
- Integrity: the owner is under investigation for suspected tax evasion. This raises doubt about management's integrity and about whether Delta's records are reliable. The firm should run client due diligence, check public sources and discuss with the proposed predecessor auditor, with consent.
- Money laundering: tax evasion proceeds can be laundered. The firm should follow its anti-money laundering procedures and identify the beneficial owner. Any suspicion should go through the firm's money laundering reporting officer, who decides whether a report to the relevant authority is needed. The firm must avoid tipping off: it should not question the client about the suspicion or hint that a report may be made.
- Independence and familiarity: the finance director was recently an audit manager in the firm, but on Alpha, not Delta. The firm must assess the threat that arises when a former member of the firm takes a key management position at a client. The specific Code rules on former audit team members joining a client apply to the client they audited, which is Alpha, so they do not directly apply to Delta. The threat is evaluated on the facts, such as his continuing connections with the firm. Because he left only two months ago, a familiarity threat may remain from his close relationships with the firm's staff. Safeguards: check that he has no outstanding payments, benefits or continuing involvement with the firm, and that no individual from the Delta team has close relationships with him.
- Confidentiality of Alpha: he holds confidential information about Alpha. The firm must protect it, remind him of his duty of confidentiality, and make sure the information is not used or passed on in the Delta engagement.
- Fee: a very low fee creates a self-interest threat to quality. The firm needs to confirm that the fee allows adequate time and staff for the audit. The firm should not cut the work to match the price.
- Competence and resources: confirm that the firm has staff with relevant industry knowledge and time to complete the work. Check if the engagement would stretch its resources.
- Conflicts: check whether there is any conflict between Delta and Alpha, for example they trade with each other. Confidentiality must be kept for both.
- Reason for the engagement: ask why Delta is changing auditor or seeking an audit. Contact the previous auditor to find out about any disagreements or concerns.
- Conclude: the integrity concern and money laundering risk are serious. Unless due diligence resolves them, the firm should decline. If it accepts, the decision should be approved by a senior partner not on the engagement, and documented.
Answer: The firm should not accept Delta unless due diligence removes the doubts about the owner's integrity and money laundering risk. Any money laundering suspicion must go through the firm's reporting officer without tipping off the client. The finance director's recent move from the firm to a key management position creates a familiarity threat that the firm must assess on facts such as his continuing connections with the firm. The specific rules on former audit team members apply to Alpha, the client he audited, not directly to Delta. The firm should check that he has no outstanding payments, benefits or continuing involvement with the firm, and that no individual from the Delta team has close relationships with him. The firm must also protect the confidential information he holds about Alpha. The very low fee creates a self-interest threat to quality. Competence, resources and conflicts must be confirmed. Given the investigation, the safer conclusion is to decline, or accept only with senior approval and documented resolution of all concerns.
Exam tips
- Use the scenario facts in every sentence. Generic ISQM 1 lists score few marks.
- Show the chain: risk or threat, why it matters, response. Markers look for all three.
- In acceptance questions, cover integrity, competence and resources, ethical compliance, conflicts and fee. Add money laundering when the scenario hints at it.
- Always reach a conclusion: accept, accept with safeguards, or decline. Professional skills marks reward a clear, reasoned recommendation.
- Keep firm-level (ISQM 1) and engagement-level (ISA 220) points separate, and label which one you are addressing.
Practice questions from Quality management (firm and engagement level)
- Brandt Audit LLP is documenting the components of its system of quality management under ISQM 1. Which of the following is one of the compon…
- Harbour & Wells, an audit firm, is revising its system under ISQM 1. The managing partner says the firm will simply keep its existing qualit…
- Harlow & Finch, an audit firm, is redesigning its system of quality management under ISQM 1. The managing partner says the firm will simply …
- Fenwick & Partners operates a firm-wide quality management system. A network of affiliated firms provides it with standard audit software an…
- Harlow & Dunmore, an audit firm, is auditing Keswick Foods plc, a listed entity. Under the firm's ISQM 1 policies, listed entity audits requ…
Firm Governance, Leadership and Ethical Requirements in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Firm Governance, Leadership and Ethical Requirements: frequently asked questions
What does ISQM 1 say about governance and leadership?
The firm must set a culture that values quality and show leadership commitment to it. It must assign ultimate responsibility and accountability for the quality system to the chief executive or managing partners, and assign operational responsibility to people with enough experience, authority and time. It must also plan resources and organisational structure to support quality.
How is the firm's risk assessment process different from engagement risk assessment?
The firm's process looks at quality risks to the whole quality management system. It asks what could stop the firm meeting its quality objectives. Engagement risk assessment under the ISAs looks at the risk of material misstatement in one client's financial statements.
What should I include in a client acceptance answer?
Cover client integrity, the firm's competence, time and resources, ability to comply with ethical requirements including independence, conflicts of interest, money laundering risk, the reason for the engagement and fee adequacy. Link each point to the scenario and end with a recommendation.
How do I answer threats and safeguards questions for audit firms?
Name the threat type, explain how it arises in the facts, and give a safeguard that fits it, such as a second partner review or removing a person from the team. If no safeguard can reduce the threat to an acceptable level, say the firm should eliminate the circumstance or decline or end the engagement.