ISQM 1 in Africa: What a Firm's System Must Evidence, and What Software Can Hold

ISQM 1 for audit firms in Kenya, Uganda, Tanzania, Rwanda, Zambia, Nigeria, Ghana, South Africa and the UAE: dates, national adoption, what inspectors are finding, and which evidence software can hold.

CS
Creodata Solutions Team
ISQM 1 in Africa: What a Firm's System Must Evidence, and What Software Can Hold

Short answer: ISQM 1 requires every audit firm to run a system of quality management, not just file a manual. Since 15 December 2022 firms must have designed and implemented that system, evaluate it at least annually, and obtain independence confirmations at least annually. Software can hold much of the evidence: engagement records, acceptance decisions, documentation custody and monitoring files. Risk assessment, policies and root-cause analysis remain the firm's judgement.

This guide is for managing partners and quality leaders in firms answering to ICPAK in Kenya, ICPAU in Uganda, NBAA in Tanzania, ICPAR in Rwanda, ZICA in Zambia, the FRC and ICAN in Nigeria, ICAG in Ghana, IRBA in South Africa and the Ministry of Economy & Tourism in the UAE.

Creodata sells practice software for audit firms, so we say plainly where we fit, and where we do not, near the end. We do not sell an ISQM 1 manual template, and a purchased manual is not a system. This is a summary for planning, not professional advice: your institute's guidance and the standard itself govern.

How ISQM 1 is built

ISQM 1 replaced ISQC 1. Where ISQC 1 asked firms for policies and procedures, ISQM 1 asks them to identify the risks to quality and respond to them. It organises the system into eight components:

  1. the firm's risk assessment process;
  2. governance and leadership;
  3. relevant ethical requirements;
  4. acceptance and continuance of client relationships and specific engagements;
  5. engagement performance;
  6. resources;
  7. information and communication;
  8. the monitoring and remediation process.

For each of the middle six, the standard sets quality objectives. The firm identifies quality risks against those objectives and designs responses. The monitoring and remediation process tests whether the responses work, finds the root causes of deficiencies and fixes them.

The dates that matter:

  • 15 December 2022. Systems of quality management had to be designed and implemented by this date (para 13). ISQM 2 on engagement quality reviews, and ISA 220 (Revised) on quality management for an individual audit, apply to audits and reviews of periods beginning on or after this date.
  • Within one year of that. The first evaluation of the system was due within one year after 15 December 2022.
  • Every year after. The individual with ultimate responsibility for the system evaluates it as of a point in time, at least annually, and concludes in one of three prescribed ways (paras 53 and 54).

Three specific requirements worth knowing:

  • Independence confirmations. The firm obtains, at least annually, a documented confirmation of compliance with independence requirements from everyone required to be independent (para 34(b)).
  • Acceptance and continuance. Decisions to accept or continue rest on enough information about the engagement and the client's integrity, and on the firm's ability to do the work properly (para 30(a)).
  • Engagement documentation. It is assembled on a timely basis after the report and appropriately maintained and retained (para 31(f)). Our guide to file assembly and retention by country covers that objective in detail.

Adoption by country

Every market in this guide applies the ISAs; how ISQM 1 reaches the firm differs.

CountryHow ISQM 1 appliesWho reviews it
KenyaAdopted by reference through the Accountants (Standards of Professional Practice and Ethical Conduct) Regulations 2022 (LN 147 of 2022), with ISQM 2 and the IESBA Code. ICPAK supports it through workshops, mandatory quality assurance training and inspection-readiness sessionsICPAK's Registration Committee; review results inform annual licence renewal
UgandaISQM 1, ISQM 2 and ISA 220 (Revised) applied from 15 December 2022ICPAU audit quality reviews, which test them, at least once every three years
TanzaniaISQM 1 and ISQM 2 effective 15 December 2022; NBAA's technical update for the fourth quarter of 2022 set out the datesNBAA audit quality review
RwandaISAs adopted without modification for all statutory audits under ICPAR's founding law. ISQM 1 is not named separately in the sources we read: confirm the position with ICPARICPAR's mandatory, risk-based quality assurance reviews
ZambiaISAs adopted without modification; IFAC lists ISQM as part of the ISA framework. We found no ZICA circular on ISQMZICA practice review, at least once every three years
NigeriaThe FRC Audit Regulations 2020 require every auditor and audit firm to run a quality management system that complies with ISQM as issued by the IAASBThe FRC: every year for firms auditing more than 20 public interest entities, every three years for others; ICAN for non-PIE auditors under delegation
GhanaISQM 1 and ISQM 2 adopted. A new firm applying for a licence must submit its documented system of quality management "as required by ISQM 1&2"ICAG's Audit Quality Monitoring department
South AfricaApplied since 15 December 2022. IRBA's quality management rules add that ultimate responsibility sits with a registered auditor and that documentation of the system is kept at least five yearsIRBA, which began inspecting whether firms' systems operate effectively in early 2024
UAEMinisterial Decision No. 195-3 of 2024, issued 30 September 2024, requires accounting firms to apply the ISAs and the International Standards on Quality Management. Decree-Law 41 of 2023 separately requires a professional performance quality control systemThe Ministry of Economy & Tourism

Two local details stand out. Ghana's licensing asks for the documented system before a firm starts, so a new firm needs its ISQM 1 evidence ready on day one. Kenya's self-review tool for quality assurance reviews asks whether the firm uses audit software, and whether working papers show who performed each procedure and when.

What inspectors are finding

The most detailed public evidence we found comes from South Africa. IRBA's 2024 Public Inspections Report found that "Firms' monitoring of their SOQMs was not performed as required by ISQM 1." It also found missing documentation of the risk assessment process, of monitoring results, and of evidence that responses to quality risks had actually been put in place. The share of inspected files needing significant improvement or referred for investigation fell from 62 percent in 2019 to 55 percent in 2024: better, but more than half.

The failures were not missing manuals. They were missing evidence that the system ran.

Ghana has raised the cost of repeating a finding. ICAG's directive of August 2026 defines a repeated thematic finding as one that recurs in two or more consecutive review cycles without remediation. A finding accepted in one review requires a documented corrective action plan before the next cycle begins. If the same finding recurs, that is prima facie evidence of professional misconduct and the member is referred to the Disciplinary Committee. A firm in Ghana now needs to show, at the next review, what it did about the last one.

ISQM 1 evidence: what software can hold, and what it cannot

Use this table to scope any system, ours or anyone else's. The last column says honestly where AuditEDMS stands.

ComponentWhat the system must showEvidence software can holdWhat remains the firm's judgementAuditEDMS
Risk assessment processQuality objectives set, quality risks identified and assessed, responses designedA controlled, versioned copy of the risk register and its approvalsIdentifying and assessing the risks; designing the responsesNot supported as a feature. It does not assess or record the system's risks
Governance and leadershipLeadership responsibility, culture, roles and resources for qualitySigned appointments and board minutes held as documentsCulture, accountability and the quality manual itselfNot supported. It does not hold or generate the firm's quality manual
Relevant ethical requirementsIndependence and ethics met; annual confirmations obtainedSigned confirmations, filed and datedAssessing threats and safeguards; deciding breachesNot supported. There is no independence confirmation workflow; keep signed confirmations in your own controlled store
Acceptance and continuanceDecisions rest on enough information about the client and the firm's abilityThe acceptance record, who approved it and when; a gate that stops work before terms are agreedWhether to accept; the integrity judgementSupported as a gate. Client acceptance and then professional clearance are stages that complete in order before the engagement letter, and the request for information cannot go out until the signed engagement letter is filed
Engagement performanceDirection, supervision and review; consultation; documentation assembled and retained (31(f))Stages completed in order with dates and names; the archive clock; documentation custody with retention dates and legal holdThe quality of the audit work and its reviewSupported for the engagement record and documentation custody. Working papers stay in your working-paper software
ResourcesCompetent people assigned; technological resources fit for purposeTime recorded by person, engagement and stage; access controlled by sign-inCompetence, capacity and assignment decisionsPartly. Timesheets and approvals show who worked on what; it does not assess competence
Information and communicationRelevant, reliable information flows within the firm and to regulatorsAn audit trail of every action; a single client file across service linesWhat is communicated and to whomPartly. Audit trail and shared client file; not a communication policy
Monitoring and remediationMonitoring performed; deficiencies evaluated; root causes found; remediation tracked; annual evaluationInspection reports, file-review results and remediation plans stored with versions; a printable history of any engagement for reviewersEvaluating deficiencies, root-cause analysis, the annual conclusionPartly. Each engagement's history prints for file reviews, and documents filed against an engagement keep their versions and audit trail; root-cause analysis and the evaluation are yours

The honest summary: software is good at proving that something happened, when, and by whom. It is no help in deciding what the risks are, whether a deficiency is severe or pervasive, or why it happened. No tool can do the second half for you.

An ISQM 1 implementation checklist

The evidence we would expect a reviewer to ask for. Adapt it to your firm's size.

  1. The risk assessment. Quality objectives, the risks identified against each, their assessment and the responses, approved by the person with ultimate responsibility.
  2. Named responsibilities. Who holds ultimate responsibility, who is operationally responsible for the system, for independence, and for monitoring.
  3. Policies and procedures. Your quality manual, written for your firm, not a purchased template left unchanged.
  4. Independence confirmations. Signed and dated for everyone required to be independent, at least annually.
  5. Acceptance and continuance records. For each engagement: the information gathered, the decision, who took it and when, before work began.
  6. Engagement records. Evidence of direction, supervision and review, and of engagement quality review where required.
  7. File assembly and retention. Evidence that files were assembled within your deadline, kept intact and retrievable, and that changes after assembly were recorded.
  8. Monitoring results. File reviews, inspection reports and their findings.
  9. Root-cause analysis and remediation. For each deficiency: the cause, the action, the owner, the date, and evidence it worked.
  10. The annual evaluation. The conclusion, as of a point in time, and what it was based on.

In South Africa, keep this documentation at least five years under IRBA's rules. In Ghana, keep the corrective action plans where the next reviewer will ask for them.

Where Creodata fits

Creodata is a Nairobi software company. AuditEDMS, our practice software for audit firms, holds the engagement record and the client file, which is where much of the evidence for items 5 to 8 on the checklist comes from.

  • Engagement performance. Each statutory audit runs through 13 stages from tender to archive. Stages complete in order, and evidence gates stop a stage completing until its document is filed. A printable compliance view shows every stage, its evidence, dates and who completed it, ready for your institute's reviewers.
  • Acceptance gate. Client acceptance and then professional clearance are stages that complete in order before the engagement letter, so the engagement is accepted only after the predecessor has been asked, and the request for information cannot go out until the signed engagement letter is on file.
  • Documentation custody and retention. Client documents are filed to your own SharePoint by client, engagement and document type, versioned and checksummed, never silently overwritten, with retention dates by document type and legal hold. An archive clock counts down from sign-off to your file-assembly deadline.
  • Monitoring evidence. When a reviewer selects a file, its history prints rather than being reconstructed, and every action on it is in the audit trail.

What it does not do: it does not run your risk assessment of the system, write or hold a quality manual template, carry out root-cause analysis, or replace your working-paper software. Its findings register follows findings raised on engagements, such as management letter points; it is not a register of the firm's own monitoring findings and their remediation. Stage templates are configuration, set up with you during implementation. See AuditEDMS for audit firms.

Frequently asked questions

Is there an ISQM 1 manual template we can use?

A template can give you a structure. But ISQM 1 requires a system built on your firm's own risk assessment and responses, so a manual adopted without that work does not meet it. Use one as a starting structure, not the answer.

How often must the system be evaluated?

At least annually, by the person with ultimate responsibility for the system, as of a point in time (ISQM 1 paras 53 and 54).

Can software make a firm ISQM 1 compliant?

No. Software can hold evidence that the system operates: acceptance records, engagement histories, documentation custody and monitoring files. Compliance depends on the firm's judgements about risks, responses and deficiencies, which remain the firm's.


See how AuditEDMS for audit firms holds the engagement record, the acceptance gate and documentation custody your quality reviewers ask for: request a pilot.

See Audit Management Software in action.