ISQM 1: Audit Quality Is Built Into the Firm, Not Demonstrated at the End
ISQM 1 replaces quality control with risk-based quality management. What changes for audit firms in Pakistan, the ICAP timeline, and what smaller practices should do.

Audit quality is no longer something a firm demonstrates at the end of an engagement. Under ISQM 1, it is something the firm has to build in from the beginning — and be able to show is working.
One of the most significant changes taking place in Pakistan's audit landscape is the move from traditional quality control towards a risk-based System of Quality Management. The difference is more than a change of name.
Quality control versus quality management
Quality control traditionally focused on whether prescribed procedures were followed. The file was reviewed, the checklist was complete, the sign-offs were in place.
ISQM 1 asks a broader question: have we designed a system that is capable of identifying and responding to the risks that could prevent us from delivering a quality engagement?
That reframes quality from something checked on each file into something managed across the whole firm.
Where quality risks come from
Quality risks arise in more places than the audit file. For example:
- Accepting a client without adequately considering integrity and independence risks
- Taking on an engagement without the necessary technical competence or resources
- Excessive workload compromising audit time and supervision
- Inadequate consultation on complex accounting or auditing matters
- Weak documentation of significant professional judgements
- Ineffective engagement review processes
- Failing to identify recurring deficiencies from previous engagements
- Treating monitoring as a compliance exercise rather than a mechanism for improvement
Every item on that list is a firm-level decision, not an audit-procedure failure. That is the point of ISQM 1.
More than an "ISQM manual"
A manual can document policies. It cannot, by itself, create quality.
A meaningful System of Quality Management requires the firm to:
Identify → Assess → Respond → Monitor → Remediate
— and then to revisit those risks continuously as the firm's circumstances change: new clients, new staff, new industries, new standards.
ICAP has emphasised that ISQM 1 represents a shift towards a proactive, integrated and risk-based approach to quality management. For firms exclusively auditing SMCs, the mandatory applicability date is now 1 July 2026.
The opportunity for smaller practices
A smaller firm does not need the infrastructure of a large firm to achieve strong audit quality. What it needs is a system that is:
- Proportionate — scaled to the firm's size and the nature of its engagements
- Documented — risks, responses and monitoring results recorded, not held in a partner's head
- Understood — every member of the team knows what the system expects of them
- Actually used — consulted when accepting clients, assigning staff and reviewing files, not filed away
For a small practice this can be a competitive advantage. Clients, regulators and lenders increasingly ask how audit quality is managed, and a firm that can answer with evidence stands apart from one that can only point to a manual.
The real test
The question should not be, "Do we have an ISQM file?"
It should be, "If someone reviewed how our firm operates tomorrow, would our system demonstrate that quality is actually being managed?"
That is the conversation the profession needs to have. At Hammad Malik & Co., it is the standard we hold ourselves to.
For companies choosing an auditor, we are glad to explain how our own system of quality management works. For practices building theirs, we advise on proportionate risk assessment, response design, monitoring and remediation.
Book a consultation