How to Conduct a Quality Management Review Under ASQM 1

The Growing Importance of ASQM 1 Quality Management Reviews

When ASQM 1 became effective, many audit and assurance firms focused on building their quality management systems, documenting policies, and aligning their processes with the new requirements. Today, the conversation has shifted.

Regulators and professional bodies are placing greater emphasis on whether a firm's System of Quality Management (SoQM) is operating effectively rather than simply existing on paper. According to the AUASB ASQM 1 Quality Management Standard, ASQM 1 introduced a risk-based approach that requires firms to continually identify quality risks, assess responses, monitor outcomes, and remediate deficiencies where necessary.

This shift comes at a time when audit quality remains a key focus area for regulators, with bodies such as the Australian National Audit Office highlighting the importance of system-level audit quality management. ASIC's audit inspection and surveillance programs continue to assess whether firms have appropriate systems and processes in place to support high-quality audits and compliance with applicable standards.

For many firms, the challenge is no longer implementing ASQM 1. It is conducting an effective quality management review that provides confidence that quality objectives are being achieved and that emerging risks are being identified before they impact engagement outcomes.

This guide outlines a practical approach to conducting an ASQM 1 quality management review, from planning and evidence gathering through to evaluation, remediation, and ongoing compliance.

Preparing for an ASQM 1 Quality Management Review

A successful review begins long before testing starts. Proper planning helps ensure the review focuses on the areas that present the greatest risk to engagement quality and compliance.

Define the Scope

  • The first step is determining what the review will cover.
  • Depending on the size and complexity of the firm, the review may focus on:
  • The entire System of Quality Management
  • Specific quality objectives
  • High-risk engagements
  • Particular service lines
  • Areas impacted by organisational or regulatory changes

The scope should reflect the firm's current risk profile and operating environment.

Review Previous Findings

Past reviews often provide valuable guidance on where attention should be directed.

Consider:

  • Prior internal inspection results
  • Historical deficiencies
  • Outstanding remediation plans
  • External inspection findings
  • Recurring quality issues

Repeated findings can indicate that previous remediation efforts have not fully addressed the underlying cause.

Identify Current Quality Risks

Quality management reviews should focus on today's risks rather than last year's concerns.

Common risk areas include:

  • Staff turnover and resource shortages
  • Expansion into new service offerings
  • Increased use of technology
  • Changes in regulatory requirements
  • Reliance on external specialists or service providers

These factors can significantly influence engagement quality if they are not properly managed.

Gather Relevant Evidence

Before testing begins, reviewers should collect evidence that supports an objective assessment of the SoQM.

Key documentation may include:

  • Quality management policies
  • Independence declarations
  • Client acceptance records
  • Engagement files
  • Training records
  • Monitoring reports
  • Remediation plans

A quality management review should be evidence-driven. Policies alone do not demonstrate whether quality controls are operating effectively in practice.

What Documentation and Evidence Should Be Reviewed?

One of the most valuable aspects of a quality management review is understanding whether day-to-day actions align with documented policies and procedures.

Rather than reviewing documents in isolation, firms should evaluate how evidence supports the achievement of quality objectives.

Quality Management Area

Evidence to Review

Governance & Leadership

Quality objectives, leadership communications, accountability records

Ethical Requirements

Independence declarations, ethics training records, breach logs

Client Acceptance & Continuance

Acceptance checklists, risk assessments, continuance evaluations

Engagement Performance

Engagement files, review notes, consultation records

Resources

Competency records, CPD logs, workforce planning documents

Monitoring & Remediation

Inspection reports, deficiency registers, remediation plans

Focus on Governance and Leadership

As highlighted in CPA Australia's guidance on ASQM 1, leadership is expected to establish and reinforce a culture that prioritises quality throughout the firm. Reviewers should look for evidence that quality objectives are communicated consistently and supported by clear accountability structures.

Assess Ethical Compliance

Ethical requirements remain fundamental to audit quality.

Review evidence demonstrating:

  • Independence compliance
  • Conflict management procedures
  • Ethics training completion
  • Monitoring of ethical breaches

The objective is to confirm that ethical requirements are embedded into daily operations rather than treated as an administrative exercise.

Review Engagement Performance

Engagement files often provide the clearest indication of whether quality procedures are working effectively.

Reviewers should assess whether engagement teams are:

  • Following firm methodology
  • Documenting key judgements appropriately
  • Completing reviews on time
  • Applying consultation requirements where necessary

Examine Monitoring Activities

ASQM 1 requires firms to establish monitoring and remediation processes that provide reliable information about the effectiveness of the SoQM.

Reviewers should therefore examine:

  • Internal inspection findings
  • Monitoring activities performed during the year
  • Root cause analysis documentation
  • Corrective actions implemented
  • Follow-up reviews

The quality of these activities often determines whether deficiencies are identified early or allowed to develop into larger issues.

Step-by-Step Process for Conducting an ASQM 1 Quality Management Review

Once the scope has been established and evidence has been gathered, firms can begin evaluating whether their System of Quality Management (SoQM) is achieving its intended objectives.

A structured review process helps ensure findings are evidence-based, consistent, and aligned with ASQM 1 requirements.

Step 1: Assess the Design of the SoQM

Start by evaluating whether the firm's quality management framework has been appropriately designed.

Key questions include:

  • Have relevant quality objectives been established?
  • Have quality risks been identified and assessed?
  • Are responses designed to address those risks?
  • Are quality responsibilities clearly assigned?

A firm may have documented policies and procedures, but if they do not adequately address significant quality risks, the design of the system itself may be ineffective.

Step 2: Test Operating Effectiveness

The next step is determining whether quality controls are functioning as intended in day-to-day operations.

Review whether:

  • Independence procedures are consistently followed.
  • Client acceptance processes are being applied.
  • Engagement reviews occur when required.
  • Quality-related training is completed and tracked.
  • Monitoring activities are performed as planned.

This stage often uncovers gaps between written policies and actual practice.

Step 3: Review Engagement Files

Completed engagement files provide valuable insight into how quality requirements are applied in practice.

When reviewing files, assess:

  • Compliance with firm methodology
  • Evidence of supervision and review
  • Documentation of significant judgements
  • Consultation procedures where relevant
  • Timeliness of file completion

The objective is to identify patterns rather than focus solely on isolated technical errors.

Step 4: Evaluate Findings and Form Conclusions

Once testing has been completed, findings should be evaluated collectively.

Consider:

  • The nature of deficiencies identified
  • Their potential impact on engagement quality
  • Whether issues are isolated or recurring
  • Whether quality objectives are being achieved

The conclusion should determine whether the SoQM provides reasonable assurance that the firm consistently performs quality engagements and complies with professional standards.
 

Evaluating Deficiencies, Root Causes, and Remediation Actions

Identifying a deficiency is only the first step. The real value of a quality management review comes from understanding why the issue occurred and ensuring it does not happen again.

This is why ASQM 1 places significant emphasis on monitoring and remediation. Firms are expected to investigate deficiencies, determine their root causes, and implement appropriate corrective actions.

Assess the Severity of Deficiencies

Not all findings carry the same level of risk.

Reviewers should consider:

  • How often the issue occurs
  • The number of engagements affected
  • The potential impact on audit quality
  • Whether regulatory requirements were compromised

A single isolated error may require limited action, while recurring issues across multiple engagements may indicate a broader weakness within the system.

Perform Root Cause Analysis

A remediation plan is only effective when it addresses the actual cause of the problem.

Common root causes include:

  • Inadequate training
  • Resource constraints
  • Insufficient supervision
  • Poor communication of policies
  • Technology or workflow issues
  • Ineffective monitoring processes

For example, recurring documentation deficiencies may initially appear to be technical issues. Further investigation may reveal that engagement teams are working under significant workload pressures or that review procedures are not being performed consistently.

Implement and Monitor Remediation Plans

Remediation actions should be:

  • Clearly documented
  • Assigned to accountable individuals
  • Supported by realistic timelines
  • Subject to follow-up monitoring

Examples of remediation activities include:

  • Additional staff training
  • Updates to quality policies
  • Enhanced review procedures
  • Changes to resource allocation
  • Increased monitoring frequency

The goal is not simply to close findings but to strengthen engagement quality and reduce the likelihood of future deficiencies.

Maintaining Ongoing Compliance and Conclusion

A quality management review should never be viewed as a once-a-year compliance exercise.

ASQM 1 is built around continuous improvement. As firms evolve, so do their quality risks. New technologies, staffing changes, regulatory developments, and expanding service offerings can all affect the effectiveness of the SoQM.

Best Practices for Ongoing Compliance

Firms can strengthen ongoing compliance by:

  • Conducting periodic monitoring activities throughout the year
  • Tracking quality-related metrics and recurring findings
  • Reviewing remediation progress regularly
  • Keeping risk assessments up to date
  • Ensuring leadership remains actively involved in quality oversight

Many firms are also reassessing how quality management activities are supported internally, particularly in an environment where talent shortages and increasing compliance requirements continue to place pressure on resources.

Access to specialised quality management expertise, flexible staffing models, and scalable operational support can help firms maintain review quality without diverting attention from client service delivery.

ASQM 1 Quality Management Review FAQs: Compliance, Monitoring, and Best Practices

1. What is an ASQM 1 quality management review?

An ASQM 1 quality management review evaluates whether a firm's System of Quality Management (SoQM) is effectively designed, implemented, and operating to achieve its quality objectives.

2. How often should firms review their ASQM 1 quality management system?

While firms typically perform an annual evaluation, ongoing monitoring throughout the year is essential to identify quality risks and deficiencies early.

3. What documentation should be reviewed under ASQM 1?

Common documents include engagement files, independence declarations, client acceptance records, training logs, monitoring reports, and remediation plans.

4. What are the most common ASQM 1 compliance challenges?

Firms often struggle with monitoring activities, root cause analysis, documentation consistency, remediation tracking, and maintaining adequate resources.

5. Why are monitoring and remediation important under ASQM 1?

Monitoring helps identify deficiencies, while remediation ensures corrective actions are implemented to improve quality management and maintain compliance.

Turning ASQM 1 Reviews into a Continuous Quality Improvement Process

Implementing ASQM 1 is only the starting point. The real measure of success lies in whether a firm's System of Quality Management continues to operate effectively, respond to emerging risks, and support consistent engagement quality over time.

A well-executed quality management review helps firms move beyond compliance by providing a structured framework to evaluate controls, assess risks, identify deficiencies, and implement meaningful improvements. By reviewing the right evidence, testing the effectiveness of quality responses, and addressing root causes rather than symptoms, firms can strengthen both their quality culture and operational performance.

As regulatory expectations continue to evolve, firms that embrace continuous monitoring and remediation will be better positioned to maintain compliance, improve audit quality, and build greater confidence among clients, regulators, and stakeholders. Ultimately, ASQM 1 quality management reviews are not about satisfying a standard. They are about creating a sustainable system that supports high-quality engagements and long-term professional excellence.

Finding ASQM 1 Compliance Increasingly Resource Intensive?

PABS Australia helps accounting and audit firms strengthen quality management processes, access skilled support resources, and reduce the operational burden of ongoing compliance and review activities.

Published on:

Atul Upadhyay helps businesses across Australia improve efficiency, strengthen compliance, and scale through strategic outsourcing solutions. As Senior Vice President – Business Development at PABS Australia, he works with organizations to unlock greater value from their finance operations.

Listen Exclusive Podcast On

sfamgpscpb

Contact Us

Find out more about our services and ways in which we can help you transform your business.

chatbotImg