ISQM 1 in Africa: What a Firm's System Must Evidence, and What Software Can Hold
ISQM 1 for audit firms in Kenya, Uganda, Tanzania, Rwanda, Zambia, Nigeria, Ghana, South Africa and the UAE: dates, national adoption, what inspectors are finding, and which evidence software can hold.

Short answer: ISQM 1 requires every audit firm to run a system of quality management, not just file a manual. Since 15 December 2022 firms must have designed and implemented that system, evaluate it at least annually, and obtain independence confirmations at least annually. Software can hold much of the evidence: engagement records, acceptance decisions, documentation custody and monitoring files. Risk assessment, policies and root-cause analysis remain the firm's judgement.
This guide is for managing partners and quality leaders in firms answering to ICPAK in Kenya, ICPAU in Uganda, NBAA in Tanzania, ICPAR in Rwanda, ZICA in Zambia, the FRC and ICAN in Nigeria, ICAG in Ghana, IRBA in South Africa and the Ministry of Economy & Tourism in the UAE.
Creodata sells practice software for audit firms, so we say plainly where we fit, and where we do not, near the end. We do not sell an ISQM 1 manual template, and a purchased manual is not a system. This is a summary for planning, not professional advice: your institute's guidance and the standard itself govern.
How ISQM 1 is built
ISQM 1 replaced ISQC 1. Where ISQC 1 asked firms for policies and procedures, ISQM 1 asks them to identify the risks to quality and respond to them. It organises the system into eight components:
- the firm's risk assessment process;
- governance and leadership;
- relevant ethical requirements;
- acceptance and continuance of client relationships and specific engagements;
- engagement performance;
- resources;
- information and communication;
- the monitoring and remediation process.
For each of the middle six, the standard sets quality objectives. The firm identifies quality risks against those objectives and designs responses. The monitoring and remediation process tests whether the responses work, finds the root causes of deficiencies and fixes them.
The dates that matter:
- 15 December 2022. Systems of quality management had to be designed and implemented by this date (para 13). ISQM 2 on engagement quality reviews, and ISA 220 (Revised) on quality management for an individual audit, apply to audits and reviews of periods beginning on or after this date.
- Within one year of that. The first evaluation of the system was due within one year after 15 December 2022.
- Every year after. The individual with ultimate responsibility for the system evaluates it as of a point in time, at least annually, and concludes in one of three prescribed ways (paras 53 and 54).
Three specific requirements worth knowing:
- Independence confirmations. The firm obtains, at least annually, a documented confirmation of compliance with independence requirements from everyone required to be independent (para 34(b)).
- Acceptance and continuance. Decisions to accept or continue rest on enough information about the engagement and the client's integrity, and on the firm's ability to do the work properly (para 30(a)).
- Engagement documentation. It is assembled on a timely basis after the report and appropriately maintained and retained (para 31(f)). Our guide to file assembly and retention by country covers that objective in detail.
Adoption by country
Every market in this guide applies the ISAs; how ISQM 1 reaches the firm differs.
| Country | How ISQM 1 applies | Who reviews it |
|---|---|---|
| Kenya | Adopted by reference through the Accountants (Standards of Professional Practice and Ethical Conduct) Regulations 2022 (LN 147 of 2022), with ISQM 2 and the IESBA Code. ICPAK supports it through workshops, mandatory quality assurance training and inspection-readiness sessions | ICPAK's Registration Committee; review results inform annual licence renewal |
| Uganda | ISQM 1, ISQM 2 and ISA 220 (Revised) applied from 15 December 2022 | ICPAU audit quality reviews, which test them, at least once every three years |
| Tanzania | ISQM 1 and ISQM 2 effective 15 December 2022; NBAA's technical update for the fourth quarter of 2022 set out the dates | NBAA audit quality review |
| Rwanda | ISAs adopted without modification for all statutory audits under ICPAR's founding law. ISQM 1 is not named separately in the sources we read: confirm the position with ICPAR | ICPAR's mandatory, risk-based quality assurance reviews |
| Zambia | ISAs adopted without modification; IFAC lists ISQM as part of the ISA framework. We found no ZICA circular on ISQM | ZICA practice review, at least once every three years |
| Nigeria | The FRC Audit Regulations 2020 require every auditor and audit firm to run a quality management system that complies with ISQM as issued by the IAASB | The FRC: every year for firms auditing more than 20 public interest entities, every three years for others; ICAN for non-PIE auditors under delegation |
| Ghana | ISQM 1 and ISQM 2 adopted. A new firm applying for a licence must submit its documented system of quality management "as required by ISQM 1&2" | ICAG's Audit Quality Monitoring department |
| South Africa | Applied since 15 December 2022. IRBA's quality management rules add that ultimate responsibility sits with a registered auditor and that documentation of the system is kept at least five years | IRBA, which began inspecting whether firms' systems operate effectively in early 2024 |
| UAE | Ministerial Decision No. 195-3 of 2024, issued 30 September 2024, requires accounting firms to apply the ISAs and the International Standards on Quality Management. Decree-Law 41 of 2023 separately requires a professional performance quality control system | The Ministry of Economy & Tourism |
Two local details stand out. Ghana's licensing asks for the documented system before a firm starts, so a new firm needs its ISQM 1 evidence ready on day one. Kenya's self-review tool for quality assurance reviews asks whether the firm uses audit software, and whether working papers show who performed each procedure and when.
What inspectors are finding
The most detailed public evidence we found comes from South Africa. IRBA's 2024 Public Inspections Report found that "Firms' monitoring of their SOQMs was not performed as required by ISQM 1." It also found missing documentation of the risk assessment process, of monitoring results, and of evidence that responses to quality risks had actually been put in place. The share of inspected files needing significant improvement or referred for investigation fell from 62 percent in 2019 to 55 percent in 2024: better, but more than half.
The failures were not missing manuals. They were missing evidence that the system ran.
Ghana has raised the cost of repeating a finding. ICAG's directive of August 2026 defines a repeated thematic finding as one that recurs in two or more consecutive review cycles without remediation. A finding accepted in one review requires a documented corrective action plan before the next cycle begins. If the same finding recurs, that is prima facie evidence of professional misconduct and the member is referred to the Disciplinary Committee. A firm in Ghana now needs to show, at the next review, what it did about the last one.
ISQM 1 evidence: what software can hold, and what it cannot
Use this table to scope any system, ours or anyone else's. The last column says honestly where AuditEDMS stands.
| Component | What the system must show | Evidence software can hold | What remains the firm's judgement | AuditEDMS |
|---|---|---|---|---|
| Risk assessment process | Quality objectives set, quality risks identified and assessed, responses designed | A controlled, versioned copy of the risk register and its approvals | Identifying and assessing the risks; designing the responses | Not supported as a feature. It does not assess or record the system's risks |
| Governance and leadership | Leadership responsibility, culture, roles and resources for quality | Signed appointments and board minutes held as documents | Culture, accountability and the quality manual itself | Not supported. It does not hold or generate the firm's quality manual |
| Relevant ethical requirements | Independence and ethics met; annual confirmations obtained | Signed confirmations, filed and dated | Assessing threats and safeguards; deciding breaches | Not supported. There is no independence confirmation workflow; keep signed confirmations in your own controlled store |
| Acceptance and continuance | Decisions rest on enough information about the client and the firm's ability | The acceptance record, who approved it and when; a gate that stops work before terms are agreed | Whether to accept; the integrity judgement | Supported as a gate. Client acceptance and then professional clearance are stages that complete in order before the engagement letter, and the request for information cannot go out until the signed engagement letter is filed |
| Engagement performance | Direction, supervision and review; consultation; documentation assembled and retained (31(f)) | Stages completed in order with dates and names; the archive clock; documentation custody with retention dates and legal hold | The quality of the audit work and its review | Supported for the engagement record and documentation custody. Working papers stay in your working-paper software |
| Resources | Competent people assigned; technological resources fit for purpose | Time recorded by person, engagement and stage; access controlled by sign-in | Competence, capacity and assignment decisions | Partly. Timesheets and approvals show who worked on what; it does not assess competence |
| Information and communication | Relevant, reliable information flows within the firm and to regulators | An audit trail of every action; a single client file across service lines | What is communicated and to whom | Partly. Audit trail and shared client file; not a communication policy |
| Monitoring and remediation | Monitoring performed; deficiencies evaluated; root causes found; remediation tracked; annual evaluation | Inspection reports, file-review results and remediation plans stored with versions; a printable history of any engagement for reviewers | Evaluating deficiencies, root-cause analysis, the annual conclusion | Partly. Each engagement's history prints for file reviews, and documents filed against an engagement keep their versions and audit trail; root-cause analysis and the evaluation are yours |
The honest summary: software is good at proving that something happened, when, and by whom. It is no help in deciding what the risks are, whether a deficiency is severe or pervasive, or why it happened. No tool can do the second half for you.
An ISQM 1 implementation checklist
The evidence we would expect a reviewer to ask for. Adapt it to your firm's size.
- The risk assessment. Quality objectives, the risks identified against each, their assessment and the responses, approved by the person with ultimate responsibility.
- Named responsibilities. Who holds ultimate responsibility, who is operationally responsible for the system, for independence, and for monitoring.
- Policies and procedures. Your quality manual, written for your firm, not a purchased template left unchanged.
- Independence confirmations. Signed and dated for everyone required to be independent, at least annually.
- Acceptance and continuance records. For each engagement: the information gathered, the decision, who took it and when, before work began.
- Engagement records. Evidence of direction, supervision and review, and of engagement quality review where required.
- File assembly and retention. Evidence that files were assembled within your deadline, kept intact and retrievable, and that changes after assembly were recorded.
- Monitoring results. File reviews, inspection reports and their findings.
- Root-cause analysis and remediation. For each deficiency: the cause, the action, the owner, the date, and evidence it worked.
- The annual evaluation. The conclusion, as of a point in time, and what it was based on.
In South Africa, keep this documentation at least five years under IRBA's rules. In Ghana, keep the corrective action plans where the next reviewer will ask for them.
Where Creodata fits
Creodata is a Nairobi software company. AuditEDMS, our practice software for audit firms, holds the engagement record and the client file, which is where much of the evidence for items 5 to 8 on the checklist comes from.
- Engagement performance. Each statutory audit runs through 13 stages from tender to archive. Stages complete in order, and evidence gates stop a stage completing until its document is filed. A printable compliance view shows every stage, its evidence, dates and who completed it, ready for your institute's reviewers.
- Acceptance gate. Client acceptance and then professional clearance are stages that complete in order before the engagement letter, so the engagement is accepted only after the predecessor has been asked, and the request for information cannot go out until the signed engagement letter is on file.
- Documentation custody and retention. Client documents are filed to your own SharePoint by client, engagement and document type, versioned and checksummed, never silently overwritten, with retention dates by document type and legal hold. An archive clock counts down from sign-off to your file-assembly deadline.
- Monitoring evidence. When a reviewer selects a file, its history prints rather than being reconstructed, and every action on it is in the audit trail.
What it does not do: it does not run your risk assessment of the system, write or hold a quality manual template, carry out root-cause analysis, or replace your working-paper software. Its findings register follows findings raised on engagements, such as management letter points; it is not a register of the firm's own monitoring findings and their remediation. Stage templates are configuration, set up with you during implementation. See AuditEDMS for audit firms.
Frequently asked questions
Is there an ISQM 1 manual template we can use?
A template can give you a structure. But ISQM 1 requires a system built on your firm's own risk assessment and responses, so a manual adopted without that work does not meet it. Use one as a starting structure, not the answer.
How often must the system be evaluated?
At least annually, by the person with ultimate responsibility for the system, as of a point in time (ISQM 1 paras 53 and 54).
Can software make a firm ISQM 1 compliant?
No. Software can hold evidence that the system operates: acceptance records, engagement histories, documentation custody and monitoring files. Compliance depends on the firm's judgements about risks, responses and deficiencies, which remain the firm's.
See how AuditEDMS for audit firms holds the engagement record, the acceptance gate and documentation custody your quality reviewers ask for: request a pilot.