In May 2024, the PCAOB revised its quality control standard, A Firm’s System of Quality Control. PCAOB-registered CPA firms should follow this standard, which is outside the scope of this article, rather than the new AICPA standards. As the new AICPA standards are also inapplicable to government audit entities, auditors of government entities should instead apply the quality management standards of Government Auditing Standards.
Discussing solely the AICPA’s new QM standards, this article first identifies their guidelines and provides an overview of the new approach. It then focuses on the most ambitious standard (SQMS 1), and highlights some key points of the others. Examples of how these standards can lead CPA firms to change their policies and procedures are provided, as are resources that can assist in this endeavor.
The New Standards
The new standards are as follows:
Statement on Quality Management Standards (SQMS) 1, A Firm’s System of Quality Management, provides standards and guidance for CPA firms to design, implement, and monitor a system of quality management customized for their overall assurance practice and individual engagements (https://tinyurl.com/5frwvema).
SQMS 2, Engagement Quality Reviews, provides standards and guidance for CPA firms to develop policies on when to perform an engagement quality (EQ) review, how to perform the review, and who will perform these reviews (https://tinyurl.com/sz7jcxtb).
Statement on Auditing Standards (SAS) 146, Quality Management for an Engagement Conducted in Accordance with Generally Accepted Auditing Standards, provides standards and guidance for engagement partners and their teams to maintain audit engagement quality (https://tinyurl.com/37bvxkzw).
Statement on Standards for Accounting and Review Services (SSARS 26), Quality Management for an Engagement Conducted in Accordance with Statements on Standards for Accounting and Review Services, consistent with SAS 146, provides standards and guidance for engagement partners and their teams to maintain engagement quality for reviews and accounting services (https://tinyurl.com/bdzndcbr).
These standards are intended to help CPA firms enhance the quality of their audit, review, and other work. They also are consistent with International Auditing and Assurance Standards Board (IAASB)’s International Standard on Quality Management (ISQM) 1, Quality Management for Firms that Perform Audits or Reviews of Financial Statements, or Other Assurance or Related Services Engagements, (https://tinyurl.com/y27v4ty3) and ISQM 2, Engagement Quality Reviews (https://tinyurl.com/bddww3pp).
Components of a QM System
While audit and other attest standards apply to performing individual engagements, the new QM standards seek to strengthen the firm’s overall QM system; this will lead to a reconsideration of a firm’s approach to audit quality. SQMS 1 provides a comprehensive eight-component, risk-based framework of a QM system. The following are components of a QM system:
- ▪ The risk assessment process
- ▪ Governance and leadership
- ▪ Relevant ethical requirements
- ▪ Acceptance and continuing client relationships
- ▪ Engagement performance
- ▪ Resources
- ▪ Information and communication
- ▪ The monitoring and remediation process.
Risk Assessment Process
The major change from prior guidance is SQMS 1’s risk-based approach to designing, implementing, monitoring, and updating a QM system. CPAs should be generally familiar with risk-based approaches to designing internal control systems, performing audits, and conducting other engagements. CPA firms should design QM systems to reduce QM risk to an acceptable level. This approach, which requires professional judgment and thought, improves upon generic checklist approaches. A risk-based approach usually involves the following steps:
Establish quality objectives.
Firms should first ascertain their QM goals. For example, with regard to client acceptance, the firm’s objective would be to accept only engagements that it has the technical skills and experience to service in accordance with professional standards.
Determine Risks.
Risks are what can go wrong, either at the quality management or the engagement level; for example, if a partner’s bonus to garner a new client leads the firm to accept a client with questionable business practices. The firm should use professional judgment to consider conditions, events, circumstances, and actions/inactions that could drive quality risk. Firms should consider whether a reasonable possibility of the risk exists, either individually or combined with other risks, to not meet its quality objectives. These risks include the inability to provide adequate firm resources to competently grasp and complete a complex engagement, especially when auditing clients in industries that are new to the firm.
Design and Implement Responses to Address Quality Risks.
To transcend merely recognizing potential risks, CPA firms should establish policies and procedures to reduce the risk to an acceptable level. These procedures usually should be implemented on the engagement level. Procedures that could reduce those risks to an acceptable level for individual key risks should be identified during engagement acceptance. For example, if a client completed a complex transaction, the engagement team could document specific incremental procedures it will employ to satisfactorily reduce the risk to an acceptable level. A separate partner committee, independent of the engagement team, could also evaluate the sufficiency of the additional procedures.
Monitor the QM system’s effectiveness.
A firm’s annual internal inspection program could, for example, assess whether the proposed risk-mitigation procedures were indeed performed, and whether those procedures effectively reduced the risk to an acceptable level.
Remediate the QM system.
When weaknesses are found in inspections and peer reviews, the QM system should be remediated. For example, when results are not as expected, what information could have warned of such results, and what training procedures could prevent such issues from reoccurring?
Brief Examples of Applying the Risk-Based Approach
Exhibit 1 illustrates how a CPA firm might respond to three different situations using a risk-based approach to client acceptance to satisfy its objective to accept only clients and engagements that it can perform in accordance with professional standards.
EXHIBIT 1
Applying the Risk-Based Approach

Governance and Leadership
SQSM 1 emphasizes the importance of governance and leadership. Firm leaders should promote quality actions and behavior, including developing and supporting a culture that rewards quality. They should assign overall responsibility for the quality management system to those with appropriate qualifications, influence, and authority, especially in areas of firm specialization, and perhaps with experience serving as an inspector or external peer reviewer. Quality management leaders should also assess at least annually whether the firm’s QM system provides the firm with reasonable assurance of meeting its stated objectives.
Documentation helps partners and professional staff better grasp and implement the QM system.
Relevant Ethical Requirements
Devising a risk-based system of quality management can help firms reinforce the AICPA Code of Professional Conduct. QM should be consistent with the broader framework for the standards that govern professional responsibilities to pursue the public interest through integrity, objectivity, and independence. CPAs should be especially mindful of the code’s guidance on threats to independence. For example, QM systems can require partners and professional staff to not accept even immaterial client gifts and to rotate engagement partners on audit and review engagements. Firms can also positively enhance independence requirements by creating structures that enable personnel and engagement teams to communicate relevant information to the firm without fear of reprisal.
Accepting and Continuing Client Relationships
CPA firms should evaluate risk when making decisions; factors to consider include the potential client’s industry and regulatory constraints, plus its operations, organizational structure, ownership, and governance. The firm should understand a potential client’s business model, and how it is financed—focusing on its managements’ and principal owners’ integrity and ethical values. These key factors include 1) whether the client aggressively focuses on minimizing its audit fees or maximizing reported earnings; 2) whether it seeks to limit the scope of work; 3) the reasons for the proposed appointment of the firm and the non-reappointment of their previous accounting firm; and 4) the identity and business reputation of related parties. Firms can obtain needed information from internal and external sources such as previous auditors, bankers, legal counsel, and industry peers.
Resources
While the prior guidance defined “resources” as human capital and focused on human resources policies, the new standard broadens the definition to include human, technological, and intellectual resources. The new definition includes written policies, methodologies, and guides. Financial resources clearly form a key part of a quality management system, and leadership strongly affects the allocation of financial resources to perform activities within the firm’s system of quality management and to support its QM system.
Documentation
Firms should document their QM system more formally than they have before. Documentation helps partners and professional staff better grasp and implement the QM system. SQMS 1’s information and communication components include encouraging internal and external two-way communications with clients and other key parties. Firms should recognize legal and professional standards that set time limits for retention and maintenance of engagement documentation, including managing the safe custody and retrievability of supporting engagement documentation and underlying test evidence; this should include maintaining the technology that will allow the documentation to be retrieved. Firms’ documentation of their QM systems should also consider minimum retention periods.
Other Standards
SQMS 2 addresses appointing Engagement Quality (EQ) reviewers, identifying potential threats to their objectivity, giving them adequate time to perform EQ reviews, and using their assistants. Like the prior standard, SQMS 2 requires EQ reviewers to focus on significant matters and judgments.
Specifically, SQMS 2 requires the appointment of EQ reviewers to perform and document engagement quality reviews. The standard details the eligibility and responsibilities of EQ reviewers. EQ reviewers must consider threats to their objectivity and the need for “cooling-off periods.” EQ reviewers must receive adequate time and staff to perform their reviews. EQ reviewers must consider the provisions of the AICPA Code of Professional Conduct and other relevant ethical pronouncements. In addition, the nature, timing, and extent of review procedures should vary with the nature and circumstances of each engagement; for example, a shorter EQ review would be expected on less complex engagements than on more complex ones.
SAS 146 clarifies and strengthens key QM matters at the engagement level. This standard addresses auditors’ specific QM responsibilities for the firm and its engagement partners, and provides guidance to help firms adhere to the provisions of SQMS 1. Firms should obtain reasonable assurance that it has followed professional standards and applicable legal and regulatory requirements necessary to issue appropriate audit reports. The engagement team and engagement partner should do the following:
- ▪ Implement the firm’s responses to applicable quality risks, based upon applicable firm policies, including client acceptance and retention procedures.
- ▪ Given the nature and circumstances of the audit engagement, determine whether to design and implement responses at the engagement level to exceed compliance with the firm’s policies or procedures.
- ▪ Communicate information from its policies or procedures to the audit engagement team in order to support the design, implementation, and operation of its quality management system.
These procedures should provide assurance that the firm has obtained sufficient appropriate audit evidence to support the conclusions reached in the auditor’s report.
In sum, these provisions enhance overall audit engagement quality in using a risk-based approach that will help firms identify and address specific client risks. It requires substantial and meaningful engagement partner involvement throughout the audit engagement—not just at the planning and sign-off stages.
SSARS 26 amends certain Accounting and Review Services Committee sections to be consistent with SAS 146. This standard requires that firms encourage proactive management of quality at the engagement level, by emphasizing professional skepticism, enhancing the documentation of the accountant’s judgments, and reinforcing the need for robust communications during the engagement.
Firms must identify and apply the changes in QM that apply to SSARS engagements, including managing engagement team staff and documenting compliance with the firm’s QM system. Firms must also design procedures for appropriately skilled or suitably experienced members of the engagement team to perform. They must determine whether members of the engagement team collectively have the appropriate competence and capabilities to perform the engagement. Finally, firms should suggest that the engagement team depend upon firm policies or procedures to comply with the SSARS requirements, unless information about the specific engagement indicates otherwise.
Need for an Implementation Plan
CPA firms should modify their QM systems to conform to the new guidance, especially with respect to applying the risk-based approach, enhancing QM leadership, and documenting their QM system and their QM decisions. While this article summarizes key provisions, firms should study the standards in their entirety and then develop a plan to implement them by the effective date.
For Further Information
For a list of the AICPA’s goals in developing the new standards: ASB Meeting, May 11-12, 2022, Agenda Item 21, https://tinyurl.com/4vjb855d
For an AICPA summary of the new standards: AICPA & CIMA, Quality Management Standards, 2022, https://tinyurl.com/3a4fmfk6
For a checklist of the procedures to follow in implementing the new standards: AICPA and CIMA, “Firm Checklist to Guide Your Quality Management System,” November 6, 2022, https://tinyurl.com/yc69bvu5
For many CPE programs on the new standards: NYCPA Foundation for Accounting Education, offers on-line and live classes on the Quality Management Standards, such as this one given by Renee Rampulla, https://cpe.nysscpa.org/product/34381.




























