Quality Control and General Auditing Principles
Why quality control sits above the level of any single audit
Every audit examined at Intermediate level was implicitly treated as a standalone engagement, governed by the specific Standards on Auditing applicable to that one audit. This chapter opens Final-level auditing by stepping up a level: SQC 1 governs the firm's system of quality control across every engagement it performs, and SA 220 governs quality control specifically within an individual audit engagement — the distinction between a firm-wide policy framework and its application to one specific audit is itself a frequently tested conceptual point.
SQC 1: the firm's system of quality control
Elements of a system of quality control. SQC 1 requires a firm to establish policies and procedures addressing six elements: leadership responsibilities for quality within the firm (the tone at the top, establishing that quality is not negotiable against commercial pressure); relevant ethical requirements (ensuring the firm and its personnel comply with the fundamental principles and independence requirements); acceptance and continuance of client relationships and specific engagements (assessing, before accepting a new client or continuing an existing one, whether the firm has the competence, resources, and genuine independence to perform the engagement, and whether the client's integrity raises concerns); human resources (ensuring the firm has personnel with the necessary capabilities, competence, and commitment to ethical principles); engagement performance (ensuring engagements are performed in accordance with professional standards and regulatory requirements, and that appropriate consultation occurs on difficult or contentious matters); and monitoring (an ongoing process of evaluating whether the firm's quality control policies and procedures are relevant, adequate, and operating effectively in practice, not merely well-designed on paper).
Engagement quality control review. For certain engagements, most commonly audits of listed entities and other engagements the firm's own policies identify as warranting it, SQC 1 requires an engagement quality control reviewer — a partner or other suitably qualified person not otherwise involved in the engagement — to perform an objective evaluation of the significant judgements the engagement team made and the conclusions reached in forming the audit opinion, before that opinion is issued; this independence from the engagement team itself is essential to the review's genuine objectivity, since a reviewer who was themselves involved in forming the original judgements would be reviewing their own prior work, precisely the self-review threat the ethics framework identifies.
SA 220: quality control at the individual engagement level
SA 220 translates the firm's SQC 1 policies into specific responsibilities the engagement partner must discharge on each individual audit — taking overall responsibility for the audit's quality, ensuring the engagement team collectively has the appropriate competence and capabilities, ensuring compliance with relevant ethical requirements including independence, ensuring appropriate acceptance and continuance procedures have genuinely been followed for this specific client, directing, supervising and reviewing the engagement team's work, and ensuring appropriate consultation is undertaken on difficult or contentious matters. The relationship between SQC 1 and SA 220 is precisely the firm-wide-versus-engagement-specific distinction this chapter opened with: SQC 1 establishes the firm's overall system, and SA 220 requires that system to be genuinely and specifically applied to each individual engagement, with the engagement partner personally accountable for ensuring this actually happens on the specific audit under their charge, not merely trusting that the firm's general policies will somehow apply themselves.
SA 240: the auditor's responsibilities relating to fraud
The two types of fraud relevant to an audit are fraudulent financial reporting (intentional misstatements, including omissions, in financial statements designed to deceive users) and misappropriation of assets (theft of an entity's assets, often accompanied by false or misleading records to conceal the theft). The auditor's responsibility is to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error — the auditor is not responsible for preventing fraud (that is management's and those charged with governance's responsibility, through the design and operation of internal controls), and is not expected to detect immaterial fraud or fraud outside the financial statements' scope, but must maintain professional scepticism throughout the audit, recognising the possibility that a material misstatement due to fraud could exist, notwithstanding the auditor's own past experience of the entity's honesty and integrity.
Management override of controls is specifically flagged as a fraud risk present in every audit, regardless of the auditor's own risk assessment of the specific entity, because management, by virtue of its position, is uniquely positioned to override controls that otherwise appear to be operating effectively, precisely why SA 240 mandates specific procedures addressing this risk in every audit as a baseline, rather than leaving it entirely to the auditor's own risk-based discretion.
SA 250: consideration of laws and regulations
The auditor's responsibility differs based on the proximity of a law or regulation to the financial statements: for laws and regulations generally recognised as having a direct effect on the determination of material amounts and disclosures in the financial statements (tax law, for instance), the auditor obtains sufficient appropriate audit evidence regarding compliance, much as with any other material item. For other laws and regulations that do not have a direct effect on the financial statements themselves but whose non-compliance may have a material effect (such as licensing or regulatory compliance requirements whose breach could trigger penalties or an inability to continue operating), the auditor's responsibility is limited to specific, more limited procedures — inquiry of management, inspecting correspondence with regulatory authorities — reflecting that the auditor cannot reasonably be expected to have the specialised legal expertise needed to assess compliance with every law potentially applicable to an entity's operations across every jurisdiction it operates in.
SA 260: communication with those charged with governance
The auditor communicates specific matters to those charged with governance (typically the audit committee or board) — the auditor's responsibilities under the applicable auditing standards, an overview of the planned scope and timing of the audit, significant findings from the audit including significant difficulties encountered, significant matters discussed with management, and, where applicable, matters relating to the auditor's independence — this two-way communication channel exists because those charged with governance, distinct from management, have oversight responsibility for the financial reporting process and are entitled to information the auditor's work has surfaced that is relevant to discharging that oversight responsibility, information management itself might have an incentive not to volunteer.
SA 299: joint audit of financial statements
Where two or more auditors are jointly appointed to audit the same entity's financial statements (common for large public sector entities and certain regulated entities in India), each joint auditor is jointly and severally responsible for the audit work as a whole, but individually responsible only for the specific work actually divided to and performed by that auditor, based on a division of work agreed and documented among the joint auditors at the outset — each joint auditor is entitled to rely on the work performed by the other joint auditors on the divided portions allocated to them, absent any specific reason to believe that work is unreliable, and is not required to independently review or re-perform that other auditor's own divided work.
SA 402: audit considerations relating to an entity using a service organisation
Where an entity outsources a function relevant to its financial reporting (such as payroll processing, or investment custody) to a service organisation, the auditor of the entity (the "user entity") must obtain an understanding of the nature and significance of the services provided and their effect on the user entity's internal control relevant to the audit — this typically involves obtaining a Type 1 report (describing the service organisation's controls and their design at a specific point in time) or a Type 2 report (additionally testing and reporting on the operating effectiveness of those controls over a period), prepared by an independent auditor of the service organisation itself, since the user auditor generally cannot directly test controls operating within a separate organisation it has no direct access to.
Why this chapter opens the paper
Quality control and these general principles sit conceptually above every specific engagement type this paper's later chapters examine — bank audits, group audits, special purpose framework engagements — because they establish the baseline professional discipline (a firm-wide quality system, scepticism about fraud, appropriate communication with governance, proper handling of joint and service-organisation arrangements) that must be in place regardless of which specific type of engagement or entity a Final-level question happens to describe. Treat this chapter as the professional infrastructure every later chapter's more specific content assumes is already operating correctly in the background.
