← Luxembourg

The CSSF released its ISQM1 implementation thematic report

Published on 30 January 2024 Email this Share this on LinkedIn Share this on Facebook Communiqué The CSSF released its ISQM1 implementation thematic report The International Standard on Quality Management 1 (“ISQM 1” or the “Standard”) which deals with an audit firm’s responsibilities to design, implement and operate a system of quality management for audits or reviews of financial statements, or other assurance or related services engagements, entered into force on 15 December 2022 for the design and implementation part. In 2023, the CSSF studied how the approved audit firms implemented this Standard: Through a survey launched in September 2023 and for the purpose of which a questionnaire was submitted to and received from 49 approved audit firms, and By analysing the implementation of the system of quality management and examining the risk assessment process for 10 firms in scope of the CSSF 2023 quality inspection campaign. The study not only provides with key takeaways resulting from these analyses but also emphasises on the requirements of ISQM 1 dealing with Network Requirements or Network Services. In addition to the survey, the CSSF focused its work during its 2023 inspection campaign on the risk assessment process and the design and implementation of responses, highlighted best practices for each component of ISQM 1 and identified the points to be monitored and the areas for improvement on which the CSSF will focus from 2024 onward. The report may be used by audit firms for benchmarking purposes and by audit committees to gather information about how audit firms manage quality. A full version of the report is available here below: 30 January 2024 ISQM 1 Implementation – Thematic Report Studies and reports PDF (2Mb) Relevant for Public Oversight of the Audit Profession ISQM 1 implementation Thematic Report PUBLIC OVERSIGHT OF THE AUDIT PROFESSION JANUARY 2024 ISQM 1 implementation Thematic Report PUBLIC OVERSIGHT OF THE AUDIT PROFESSION JANUARY 2024 TABLE OF CONTENTS

  1. Introduction............................................................................. 2
  2. Analysis of the results of the survey on ISQM 1 implementation ..... 3 2.
  3. Introduction ....................................................................... 3 2.
  4. Results of the survey ........................................................... 4 2.2.
  5. Firms’ profile and network membership ............................ 4 2.2.
  6. Use of external service providers ..................................... 5 2.2.
  7. Responsibilities within the System of Quality Management . 6 2.2.
  8. Establishing the quality objectives ................................... 7 2.2.
  9. Identifying and assessing quality risks ............................. 8 2.2.
  10. Implementation of the mandatory responses .................... 9 2.2.
  11. Documentation of the system of quality management ........ 9 2.2.
  12. Other aspects linked to the implementation .................... 10 2.2.8.
  13. Communication to personnel ................................... 10 2.2.8.
  14. Main difficulties encountered by the audit firms ......... 10 2.2.8.
  15. Human, time, and financial investment needs ........... 11 2.2.8.
  16. Benefits expected by the firms. ............................... 12 2.
  17. Key take aways and follow-up actions ................................. 13
  18. Assessment of the design and implementation of the system of quality management for a sample of firms in the scope of the 2023 inspections .................................................................................. 14 3.
  19. Scope of inspected firms and inspection in 2023 ................... 14 3.
  20. Risk assessment process.................................................... 14 3.
  21. Analysis of the responses provided by the firms to the quality objectives and quality risks .........................................................15 3.3.
  22. Governance and Leadership component ..........................16 3.3.
  23. Relevant Ethical Requirements component ......................17 3.3.
  24. Acceptance and Continuance of Client Relationships and Specific Engagements component..............................................18 3.3.
  25. Engagement Performance component .............................19 3.3.
  26. Resources component ...................................................19 3.3.5.
  27. Human Resources ...................................................20 3.3.5.
  28. Technological Resources ..........................................20 3.3.5.
  29. Intellectual Resources .............................................21 3.3.
  30. Information and Communication component ....................21 3.
  31. Observations related to the mandatory responses ..................22 3.4.
  32. Specified responses in ISQM 1 .......................................22 3.4.
  33. Required responses in the Luxembourg supplement to ISQM 1 .................................................................................22
  34. Assessment of the design and implementation of the requirements of ISQM 1 dealing with Network Requirements or Network Services ....23 4.
  35. ISQM 1 requirements analysis .............................................23 4.
  36. CSSF expected implementation of the requirements ...............24
  37. Conclusion and next steps ........................................................25
  38. Introduction The International Standard on Quality Management 1 (hereafter “ISQM The key changes compared to the former quality control standard include: 1” or the “Standard”) has been adopted and supplemented by CSSF - Regulation N°22-01 and entered into force on 15 December 2022 for the and which operates in an iterative manner that is proactive with design and implementation part, with the first evaluation to be performed a continual flow of remediation and improvement, one year later by 15 December
  39. - a risk assessment process that applies to all the components of the system of quality management except the monitoring and ISQM 1 deals with an audit firm’s responsibilities to design, implement remediation process, and operate a system of quality management for audits or reviews of - financial statements, or other assurance or related services engagements. enhanced emphasis on the firm’s governance and leadership with increased leadership responsibilities and accountabilities, The Standard is scalable and useable by all firms. The use of professional - judgment and professional scepticism is expected to ensure the firm’s consideration of factors affecting the firm’s environment such as the use of technology, external service providers and network system of quality management is appropriately tailored to the nature and resources, services and requirements, circumstances of the firm and the engagements it performs. - ISQM 1 consists of 8 components 1: an integrated approach that reflects upon the system as a whole new information and communication requirements including communication with external parties. Luxembourg’s supplement to this ISQM 1 aimed to reflect the requirements of the Audit Law 2 stemming from the Audit Directive and Regulation as regards the internal organisation of audit firms and the organisation of their work. The objectives of the present thematic report were defined as follows: - Analyse how audit firms in Luxembourg implemented ISQM 1, - Assess the design and implementation of the system of quality management for a sample of firms that were in scope of the quality assurance reviews in 2023, - Review how these firms have dealt with the Luxembourg’s supplement to ISQM 1 in their new system, 1 The source of the chart is IAASB – Fact Sheet Introduction to ISQM 1 ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 2 Law of 23 July 2016 related to the audit profession. 2/27 - Analyse and assess how firms that are member of a network have dealt with the requirements of the Standard when applying network requirements or using network resources The study was based: On a survey of audit firms supervised by the CSSF in Luxembourg on ISQM 1 implementation, - On the analysis of documents and information provided by the firms in scope of inspection in 2023, including interviews with designated persons in charge of operational responsibilities within the system of quality management. The report may be used by audit firms for benchmarking purposes and by audit committees to gather information about how audit firms manage quality. Analysis of the results of the survey on ISQM 1 implementation and/or services. -
  40. 2.
  41. Introduction In September 2023, the CSSF conducted a survey to determine the progress made by all audit firms under its supervision in implementing ISQM
  42. It was also an opportunity to gather information about how firms had organized themselves to tackle this regulatory change. Finally, the survey aimed at understanding the difficulties encountered and the benefits expected by audit firms from the implementation of this Standard. To collect as much information as possible from firms, the CSSF elaborated a set of 54 questions which were sent to 52 audit firms. All responded to the Survey in October
  43. The questionnaire was structured in 10 sub-sections: profile of the firm (activity, headcount), membership of a network, use of external service providers, responsibilities within the system of quality management, quality objectives, quality risks, mandatory responses (Standard, Luxembourg supplement), documentation, internal communication and implementation (difficulties, investment (time, human and financial), benefits expected). Among the 52 firms to which the questionnaire was sent and on the basis of the responses received, 3 firms were excluded from the analysis of the survey results because they did not carry out audits or reviews of financial statements, or other assurance and related services engagements. Hence, the statistics and information broken down by the CSSF in the body of this document are based upon 49 audit firms’ responses. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 3/27 2.
  44. We can also notice in the diagram above that the more employees a firm Results of the survey has, the more likely the firm belongs to a network. 2.2.
  45. Firms’ profile and network 3 membership As expected, almost all the firms being part of a network (22 out of 23) have received specific requirements from the network regarding the firm’s 35 system of quality management. 30 20 firms out of 22 having received these specific requirements also leveraged resources or services provided to them by the network for the 25 20 23 system of quality management or the performance of engagements, and 18 firms indicated that they have adapted these network-provided 15 resources or services to make them appropriate for their use. 10 5 3 10 6 0 0 - 10 employees 11 - 100 employees Member of a Network Moreover, we observe that the 23 networked audit firms had the 3 4 Mid Tier Big Four No Network Among the population of 49 audit firms, 23 are members of a network, representing 47%, while the remaining 26, representing 53%, are not affiliated to any network. opportunity or planned to gather information on the monitoring activities carried out by their network (including deficiencies identified and remedial actions) mainly based on: - the use of common tools in place within the network (12 firms) for documenting and monitoring responses; and/or - the use of reports on agreed or specific procedures (7 firms). Finally, as of the date of the responses to the Survey, the system of gathering of information on monitoring activities from the network with respect to ISQM implementation was still under progress for 4 firms. 3 ISQM 1 defines a network as a larger structure: (i) that is aimed at cooperation; and (ii) that is clearly aimed at profit or cost-sharing or shares common ownership, control or management, common quality management policies or procedures, common business strategy, the use of common brand name, or a significant part of professional resources. Networks and the firms within the network may be structured in a variety of ways. For the purpose of ISQM 1, any network requirements or network services that are obtained from the network, another firm within the network or another structure or organization in the network are considered “network requirements or network services”. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 4/27 2.2.
  46. Use of external service providers ISQM 1 recognizes that a firm may use service providers when it does not have all the resources needed internally. Resources from service providers include technological, intellectual or human resources used by the firm in the operation of its system of quality management or in the performance of engagements. Component auditors from other firms not Based on the chart below that outlines the components for which firms used service providers, we observe that “Resources”, “Engagement performance” “Information and communication” and “Engagement Quality Review” are the most quoted ones which is in line with examples provided by the Standard (e.g., Component auditors, consultation, IT within the firm’s network are also considered as service providers. application…), but no audit firm reported having used service providers Responses gathered show that, out of the population of 49 audit firms, surprising considering that ISQM 1 requires the inspection of completed 35% (17 firms) used external service providers in the operation of their system of quality management or the performance of engagements. Looking at the size of these 17 audit firms we can notice that 57% of the 7 biggest firms used services providers while only 21% of the smallest for the “Monitoring and Remediation process”. This observation is engagements in the firm’s monitoring activities and that numerous small audit firms count only one audit practitioner. The CSSF would have expected that these small practices use service providers for this purpose. firms did (0-10 employees). Components involved Use of service providers by size of audit firms Resources 8 35 Engagement performance 30 25 20 26 Information and communication 5 Engagement Quality Review 5 Acceptance and Continuance of client relationships and specific engagements 15 10 7 6 0 - 10 employees 11 - 100 employees 1 3 2 1 0 Use of service providers 3 Risk assessment process 3 5 7 Mid Tier 2 0 1 2 3 4 5 6 7 8 Big Four No service providers ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 5/27 9 It is also interesting to note that there is no correlation between using necessary to fulfil that responsibility, they may delegate parts to others, service providers and belonging to a network. Indeed, we would have provided they remain responsible and accountable for their assigned expected firms that are members of a network to give priority to using responsibilities. network resources or services. However, the diagram below shows that out of the 17 firms using service providers, 9 are members of a network. Similarly, we would have expected firms that are not part of a network to make greater use of service providers, but only 8 out of 26 did. 30 Relation between network membership and use of service providers The role and responsibilities the firm is required to assign to individuals are: - Ultimate responsibility and accountability for the system of quality management, - Operational responsibility for the system of quality management, - Operational responsibility for specific aspects of the system of quality management 25 20 18 14 15 o o Compliance with independence requirements, The monitoring and remediation process. ISQM 1 clearly states that the firm cannot outsource leadership 10 9 8 Member of a Network No network 5 0 Use of service providers No service providers responsibilities to a service provider because the firm is responsible for its own system of quality management and that the individual(s) with responsibilities is(are) required to have the appropriate influence and authority within the firm. The Luxembourg supplement to ISQM 1 4 states that the firm shall ensure that the operational responsibility for the system of quality management 2.2.
  47. Responsibilities within the System of Quality Management lies with a person who is qualified as approved statutory auditor. When it comes to the allocation of the responsibilities within the firm, the size of the audit firm is logically one of the main drivers. The results of ISQM 1 requires the firm to assign responsibilities for the system of the survey, in particular the analysis of the average number of individuals quality management, and other aspects of the system of quality with responsibilities for the system of quality management, clearly management, and to hold the individuals accountable for their assigned demonstrate that the bigger the players are, the more they make a clear roles. These individuals to whom the responsibilities are assigned, are not segregation of responsibilities by having one different responsible person themselves expected to perform all procedures, tasks or actions for each of the four main responsibilities required by ISQM
  48. 4 Based on article 24

(1)g of the Audit Law ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 6/27 Average number of individuals with responsibilities for ISQM 4,0 The firms shall establish quality objectives specified by ISQM 1 and any additional ones considered necessary by the firms to achieve the 3,0 2,6 2.2.4. Establishing the quality objectives objectives of the system of quality management. ISQM 1 requires specific quality objectives for the following components 1,3 as specified in its paragraphs 28 to 33: 0 - 10 employees 11 - 100 employees Mid Tier Big Four However, we have noticed for 6 audit firms that the operational responsibility for the system of quality management was not assigned to an approved statutory auditor. The CSSF will revert directly to these firms - Governance and Leadership, - Relevant Ethical requirements, - Acceptance and Continuance of Client Relationships and Specific Engagements, - Engagement Performance, - Resources, and - Information and Communication. However, there may be circumstances when a quality objective, or an for them to assign the adequate person. Moreover, 10 firms out of 49 have indicated that certain operational responsibilities have been delegated mainly to the business process aspect thereof, is not relevant because of the nature and circumstances of the firm and its engagements. owners or functions leaders. The survey highlighted that 100% of the approved audit firms declared While ISQM 1 does not specify who is required to Distinction between operation and monitoring activities perform monitoring activities, 17 firms have made within their system of quality management a distinction between those responsible for 25 20 15 responsible monitoring 10 activities, while 32 firms did not. 5 Here again, practice the size determines of the 33 of the Standard for the abovementioned various components. 30 operational aspects and those for 32 35 having established all the quality objectives required by paragraphs 28 to 17 0 the Yes No distinction. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 7/27 In the details, for 33 firms (67%) the quality 2.2.5. Quality objectives Identifying and assessing quality-related risks focuses on what can go objectives established are identical to the Standard, 11 while 11 (23%) established creating sub-objectives or instance by wrong in achieving quality objectives. ISQM 1 aims to focus on the risks that have the greatest impact and includes a threshold in the definition of quality risk. A risk qualifies as a quality risk when it meets both criteria: them with adjustments, by for 33 making 5 - The risk has a reasonable possibility of occurring, - The risk has a reasonable possibility of individually, or in other groupings. combination with other risks, adversely affecting the achievement For 5 firms (10%), the adaptation of internal procedures and the quality objectives’ Identifying and assessing quality risks requirements Yes identically Yes with changes (establishment of sub-objectives, other groupings) Yes partially are still being formalised. of one or more quality objectives. The firm exercises professional judgment in determining whether a risk meets the threshold. Quality risk assessment does not necessarily have to involve formal ratings, although audit firms are not prevented from using them. In this context, the survey revealed that most of the firms (78%) have In addition to the quality objectives prescribed by paragraphs 28 to 33 of adopted a quality risk assessment matrix putting in perspective the the Standard, 3 firms (6%) have established additional quality objectives probability of occurrence of identified quality risks and their related impact mainly for the “Acceptance and Continuance of Client Relationships and on the achievement of the quality objectives. Specific Engagements” to include specific risks and responses for antimoney laundering and combatting the financing of terrorism. This matrix, for 66% of those firms, embeds 3 levels of risks (usually being 5 “high”, “medium” and “low”). It is also interesting to notice that 29% 3 2 2 levels 3 3 levels 4 levels of the firms have created very detailed in-house matrices underpinned with a spectrum of 4, 5 or more than 5 different Levels of risks 25 5 levels > 5 levels levels of identified risks. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 8/27 2.2.6. Implementation of the mandatory Implementation of responses responses 3 Full implementation of the specified responses required by the Standard and the Luxembourg supplement to ISQM 1 1 ISQM 1 requires the firm to design and implement responses that properly address the quality risks. In doing this, the firm needs to think to the reasons for the assessments given to the quality risks and to consider Partial implementation of the specified responses required by the Standard and the Luxembourg supplement to ISQM 1 whether a response alone is sufficient or whether a combination of responses is needed. A firm may also design and implement a response that addresses multiple quality risks related to more than one quality objective across different components. Paragraph 34 of ISQM 1 includes some specified responses that the firm 45 is required to design and implement. These specified responses would not The specified responses required by the Standard were not implemented fully address all quality risks and the firm is expected to design and implement additional responses. Although these responses are specified, the nature, timing and extent of the response will vary, given the nature 2.2.7. Documentation of the system of quality and circumstances of the firm. management The Luxembourg supplement to ISQM 1 also includes additional responses that the firm is required to design and implement based on the Audit Law ISQM 1 does not prescribe every matter that needs to be documented by requirements. the firm as it will depend on the size and complexity of the firm and the The firms’ responses to the survey highlight that 98% of the firms types of engagements it performs. declared having implemented or partially implemented the specified ISQM 1 has set 3 principles in the preparation of the documentation, it responses required in paragraph 34 of the Standard and the additional shall be sufficient to: responses required in the Luxembourg supplement to ISQM 1, pursuant to CSSF Regulation N° 22-01 dated 11 January 2022. - Support a consistent understanding of the system of quality management by personnel, including an understanding of their roles and responsibilities with respect to the system of quality management and the performance of engagements, - Support the consistent implementation and operation of the responses, and ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 9/27 - Provide evidence of the design, implementation and operation of 2.2.8. the responses, to support the evaluation of the system of quality implementation management by the individual(
  1. s)assigned ultimate responsibility and accountability for the system of quality management. In the survey, we asked firms how they documented their risk assessment, their monitoring activities and remedial actions. Firms responded that they use different types of software or a combination of several software for the documentation of their system of quality management. Microsoft Excel is the most represented software, used by 33 firms and for both their risk assessment and their monitoring activities/remedial actions. 16 audit firms have turned to service providers that developed manuals, toolkits and software solutions for all or part of their ISQM 1 Other aspects linked to the 2.2.8.1. Communication to personnel 94% of the firms have trained or made all their employees aware of their system of quality management. For 40 firms out of 49, the documentation of the system of quality management is accessible to all personnel, which according to them reinforces employees’ awareness. The firms make the quality management documentation available via different supports, by using one or a combination of several supports and tools, such as: activities, and network integrated software is also quite well represented - dedicated folder(
  2. s)on the firm’s internal IT system, with 9 audit firms. - dedicated folder(
  3. s)on the IT server of the international global Lately, some firms are currently developing their own specific software and a few others indicated making use of tools such as Microsoft Word for ISQM 1 internal documentation purposes, in complement to Microsoft Excel, specific software or network integrated software. 35 33 Tools used for the documentation 30 - internal training/presentations, - Intranet/SharePoint, - procedures and quality manual, and/or - dedicated communication. firms 20 13 While designing and implementing their system of quality management 9 10 5 software, 2.2.8.2. Main difficulties encountered by the audit 25 15 network the firm belongs to, - 3 based on ISQM 1, except for 5 firms having reported no issues, many 2 firms faced the following main difficulties and/or challenges: 0 Excel file for risk Specific software for Specific software for Network software assessment, risk assessment, risk assessment only monitoring activities monitoring activities & remedial actions & remedial actions ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 Other 10/27 - the size of the firm: as reported by several actors, being a small or very small audit firm made the exercise of designing and - implementing a system of quality management very challenging, 25 considering the large spectrum of requirements of the Standard 20 that, according to them, hardly fits into such small or very small 15 audit practice environments, 10 the time dedicated to ISQM 1 implementation by the personnel implement the appropriate and adapted system of quality management was another challenge, - the intrinsic exercise of identifying and assessing quality risks was difficult to perform for several firms, and - the documentation: the firms struggled to formalise and/or update the policies and procedures manuals. 2.2.8.3. Human, time, and financial investment needs First Time implementation The survey included questions relating to the human, time, and financial effort that the firms needed to implement ISQM 1. We are pointing here, some of the main outcome of the analysis of responses. 1 assigned 11 “full-time to ISQM implementation in 38 audit firms and between 2 and 10 FTE in 11 firms (mainly Big <1 1 Four and Mid-Tier Firms at 2-10 the top of the range). Most of the firms dedicated a significant number of hours for the purpose of designing and implementing the system of quality management as required by ISQM 1. The spectrum of time spent by dedicated personnel spreads out from less than 1 month to more than 6 months. The period of involvement of the FTEs of the Big Four Mid-Tier was and firms generally longer than that of small firms, Time investment (to implement ISQM) 16 14 12 6 months or more 2 than 6 months, 0 due to their size more complex organisation. 3 1 8 4 almost 5 10 6 i.e. and ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 than equivalent” (or “FTE”) was 15 paragraph 2.2.8.3., own audit firm activities and environment in order to design and less 0 constraints by the entities concerned. This is further detailed in analysing and interpreting the Standard, putting in perspective its on the left-hand side, 1 or 23 5 involved in each audit firm was reported as one of the main - As represented in the table Human investment in FTE to implement ISQM 12 3 9 Less than one From 1 to 3 month months 0-10 employees Mid Tier 6 3 1 6 From 3 to 6 More than 6 months months 11-100 employees Big Four 11/27 Nevertheless, while the large firms spent more hours and over a longer period developing or creating their system of quality management in line Budget in days/person with the requirements of the Standard, small firms, due to the reduced 60 number of people involved, were the most impacted in their day-to-day 50 operations and business. 40 As regards the financial aspect, apart from the cost of cumulative hours 30 spent by the personnel and responsible persons involved in implementing 20 ISQM 1, the financial cost of compliance with the Standard also includes for several firms the one-off cost of acquiring dedicated software, adapting in-house software, or existing network software. 10 29 28 11 0 < 10 Budget for annual maintenance and update of the system of for the Human needs in FTE for monitoring activities the monitoring activities, 25 44 firms indicated that 1 20 or less FTE would be 15 dedicated to this activity, 10 which is in line with what 5 the firms have declared 0 for implementation. 23 21 2 51-100 1 1 > 100 Update of the system of quality management estimated human resources plan for 11-50 Monitoring activities and remedial actions quality management and monitoring and remediation activities As 10 We can note a similarity between the time allocated to maintaining and updating the system of quality management and the time allocated to monitoring and remedial activities. Overall, the vast majority of firms
(39)5 planned to allocate less than 50 days per person for each of the 2 activities, bearing in mind that firms dedicate 1 or less FTE for each activity. <1 1 2-10 2.2.8.4. Benefits expected by the firms Finally, the survey was also an opportunity to collect the benefits expected The diagram below points out the budget in days/person that the firms by the firms following the investments made to implement and comply intend to allocate to the maintenance of their system of quality with the requirements of the Standard. management and to the monitoring activities and remedial actions, on an annual basis: The diagram below highlights the most quoted expected benefits, that are the improvement of the quality of the audits performed, a more efficient internal organisation and internal control and a better risk management. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 12/27 2.3. Benefits expected Based on some responses to the survey it appears that scalability and 4 Few (or
  1. no)benefits expected more precisely the scale back to fit the nature and circumstances of smaller firm with low complexity, is raising many application concerns. 24 Improvement of quality The CSSF is convinced that scaling back ISQM 1 requirements for smaller 12 More efficient internal control firms with low complexity is achievable at the level of: 11 Better risk management / Risk reduction - the objectives that are adaptable, - the risks that can broad and overarching without needing any granularity, and 24 Other 0 5 10 15 20 25 30 - expectations mentioned by other players, such as: identified for the new components of ISQM 1. The CSSF has identified several areas for follow-up action in 2024: - awareness / culture for quality enhancement, - clarifying expectations of external service providers, - identify respond to deficiencies the responses that can be built on what was already in place with the previous standard but that nevertheless need to address risks The “Other” category in the table above provides other interesting and Key takeaways and follow-up actions more promptly effectively, - better documentation and control of certain activities, and - more transparency towards the public. and the use of external service providers and the application of ISQM 1 requirements to those, - the people to which responsibilities foreseen in the Standard are assigned (in terms of experience (including qualification), knowledge, time, influence and authority), - for firms that are member of a network, the network requirements and the network resources or services that are used locally in the system of quality management (see also paragraph 4.), - the implementation of the specified responses required by the Standard and the requested responses of the Audit law that are reflected in the Luxembourg supplement to ISQM 1 (see also paragraph 3.4.), and - the evolution of the resources involved in the System of quality management (in terms of number of people involved and allocated time). ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 13/27 3. Assessment of the design and implementation of the system of quality management for a sample of firms in the scope of the 2023 inspections The review consisted of interviews and requests for information relating to the risk assessment process. Based on the documentation submitted to the CSSF, the latter analysed compliance with ISQM 1 requirements considering the flexibility of the Standard which provides that the processes must be adapted depending on the circumstances and the nature of the engagements carried out by the firm. As it was a first-time implementation review, the CSSF mainly provided 3.1. Scope of inspected firms and inspection in 2023 As part of its 2023 annual work programme, the CSSF started analysing the implementation of ISQM 1 in the different firms reviewed by examining their risk assessment process in order to ensure the quality objectives have been established, that the quality risks have been identified and assessed and that responses have been put in place to recommendations on areas for improvement. 3.2. Risk assessment process All firms have conducted a risk assessment process in accordance with the requirements of the Standard and produced a matrix of quality objectives, quality risks and responses to these risks for all components. The 6 audit firms that are member of a network were provided a software address these risks. tool to document their risk assessment, the 4 other ones use an Excel file. Under the 2023 programme, 10 firms were reviewed: Firms that belong to a network had to consider the network requirements - that include globally prescribed quality objectives, quality risks and 5 firms that have more responses in building their own risk assessment matrix. than 100 employees, all Following the risk assessment process, none of the firms defined members of a network, - 2 firms that have between 11 and 100 employees, including 1 member of a network, and - 3 firms between that 0 and have 10 employees, none is a member of a network. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 > 100 employees 50% 0-10 employees 30% 11-100 employees 20% additional quality objectives but 50% of them defined sub-objectives or made other groupings. Only one firm identified additional quality risks in order to assign the responses foreseen in the Luxembourg supplement to ISQM 1. For almost all the firms inspected, the quality risks were derived directly from the quality objectives specified in the paragraphs 28 to 33 of the Standard, with a level of granularity that varies according to the size and complexity of the firm but also according to the complexity of the component. 14/27 For example, for the Relevant Ethical Requirements component, the quality objectives the firm shall establish are the following: 3.3.
  2. a)The firm and its personnel: i. Understand the relevant ethical requirements to which the firm and the firm’s engagements are subject; and ii. Fulfil their responsibilities in relation to the relevant ethical requirements to which the firm and the firm’s engagements are subject.
  3. b)Others, including the network, network firms, individuals in the network or network firms, or service providers, who are subject i. ii. Analysis of the responses provided by the firms to the quality objectives and quality risks The CSSF has analysed all responses to quality risks the audit firms documented in their risk assessment per component. The number of responses varies widely from an objective to another and from a quality risk to another. This amplitude is also linked to the size and complexity of firms. We have identified here after, for each component, the most frequently to the relevant ethical requirements to which the firm and the designed responses and/or most appropriate ones. The CSSF wants to firm’s engagements are subject: reiterate that all these responses do not need to be implemented, firms Understand the relevant ethical requirements that apply to have to exercise professional judgement in determining the responses them; and that are appropriate to the size and complexity of their organisation and Fulfil their responsibilities in relation to the relevant ethical the engagement they performed. requirements that apply to them. The number of quality risks that the firms identified and assessed for these objectives varies from 2 derived from the 2 parts of the objectives (with different grouping in some cases) to several dozen when the firm has thought in terms of business processes. 8 firms adopted a 2-Levels or 3-Levels risk assessment, one firm did not specify quality risk levels and another one has a model with 12-levels. The quality risks assessed as “High” by the firms also vary widely depending on their professional judgment and on the nature and circumstances of the firm and the engagements they perform. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 15/27 3.3.1. • Governance and Leadership component • the review of Key performance Indicators (KPIs) or Audit Adoption of a code of conduct and mechanisms to sanction Quality Indicators (AQIs) in terms of financial results, human behaviours not aligned with this code. • resources need, operational priorities, risks and quality. Setting up of channels (internal and external) for reporting concerns and issues of a sensitive nature (whistleblowing, • in charge of investigating, responding, of ethical culture and ethics resources. Responses to the and survey(
  4. s)are analysed and actions are taken on issues proposing actions and eventually sanctions to the cases. • identified. Adoption of an accountability framework to support the commitment to quality. • Establishment of a consistent and fair process to evaluate assigned with system of quality management responsibilities). Process for the management roles responsibilities appropriate appointment and (including competency • Process to evaluate the deficiencies identified during external inspections personnel for their accountabilities (including the individuals • Implementation of annual survey(
  5. s)to obtain personnel feedback on the firm’s quality culture and on the effectiveness complaints and allegations), designation of an appropriate responsible Execution of the budget includes analysis of the deviations and of system of assessing and individuals quality to and management, in monitoring perform root the System of cause analysis, implement quality remediation action plan, and communicate internally and externally. senior management that they have the capability based on their experience and knowledge and sufficient time based on the workload information). • Preparation of a strategic plan (including a commitment to obtain sufficient Human, Financial, Intellectual and Technological Resources to support the quality) and an annual budget that is consistent with the strategic plan. • Maintenance and execution of a quality communication plan that delivers through different channels and mechanisms clear and consistent quality-focused messages. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 16/27 3.3.2. Relevant Ethical • Process to ensure timely and accurate information on audit clients (including global ultimate parent and affiliates) are included in the Requirements component independence systems. • Process to ensure relevant personnel and firm do not hold restricted investments. • • when joining the firm or being promoted) that they have read, Implementation of policies, procedures and guidance on Relevant understood, and complied with the Relevant Ethical Requirements Ethical Requirements that are regularly updated and comply with (including laws and regulation. • Setting up of communication and awareness plan on Relevant Ethical Requirements (including Confidentiality, Security and Establishment of a taxonomy of permissible services. • Implementation of policies and procedures for • identifying, causes of the breaches. Ethical and Independence consultations. These consultations are assigned to the appropriate experts and reviewed at different level depending on the complexity of the subject. • Process to evaluate Business or other direct and indirect continuance forms, risk profile, independence, and conflict checks) and ensure agreements/contracts contain appropriate ethical • awareness and Performance of on-going and periodic monitoring activities: o Monitoring of timely completion of independence confirmation, follow up and resolution of exceptions (including disciplinary procedures). o Monitoring of compliance with the learning requirements, o Monitoring of the permissibility of firm’s financial investments o Monitoring of personnel reported financial investments to results to training tests, resolution, and escalation procedures. and business relationships. identify outstanding and exceptions (including conclusion on regulatory breach or policy violation). o Annual Personal Independence Compliance Testing (including o Monitoring of inducements received and given. o ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 and communicated on an annual basis to all staff and to relevant third relationships prior acceptation and annually (Acceptation and requirements. privacy Mandatory Ethical and Independence learning requirements are requirements, including action plan to address and remediate the Mandatory and parties. communicating, evaluating, and reporting breaches of ethical • confidentiality understanding of the disciplinary policies). Privacy topics). • Personnel are required to complete an annual confirmation (and reporting of exceptions and disciplinary process). Monitoring of the rotation requirements (partners, Reviewers, Firm, Senior personnel). 17/27 EQ 3.3.3. o Acceptance and Continuance of Client Relationships and Specific o • o Development of a strategic business planning including: o o o consideration for resources need, compliance with laws and regulation, reputation risk, commercial risk. make Acceptance and Continuance decisions: • o procedures on prospective clients and name screening of the of the Acceptance & Continuance o • Setting up of IT controls on the Acceptance & Continuance system: o All mandatory fields must be completed to submit the o Overall risk rating automatically calculated based on the o Generated risk can only be manually increased not decreased. questionnaire. answers to questions. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 & Continuance process is completed and The firm becomes aware of information subsequent to accepting or continuing a client relationship or specific The firm is obligated by law or regulation to accept a client relationship or specific engagement. Establishment of a standard template for engagement letters, any deviation to the standard should be approved by Risk Management questionnaires and requested documentation • Acceptance or specific engagement. Use of dedicated forms/questionnaires and tools for Acceptance & completion The engagement code can be opened only after the known prior to accepting or continuing the client relationship when issues have been identified. on Acceptance & Continuance questionnaires are approved based on the approval grid and all high-risk clients require Risk relationship or specific engagement had that information been Independence and conflict check with required consultation Training submit engagement that would have caused it to decline the client Continuance with an approval grid based on the potential risks • to consultation when: Backgrounds checks and Anti Money Laundering due diligence associated with the Acceptance & Continuance of the engagement permitted Implementation of policies and procedures including mandatory shareholders. Analysis of any hit. • are approved. client, its legal representatives, the beneficial owners, and its o individuals Management approval. focus on terms of clients, markets, and industries, Establishment of processes to obtain the information needed to approved questionnaires (interface between Human Resources system and Acceptance & Continuance system to transfer the list). Engagements component • Only function. • Performance of an annual portfolio risk review • Performance of on-going and periodic monitoring activities: o Periodic compliance testing with Acceptance & Continuance o Periodic critical review of the questionnaires. o policies and procedures. Monitoring of compliance with learning requirements for Acceptance & Continuance. 18/27 o 3.3.4. Engagement Performance component • Training on firm's methodologies including professional scepticism Implementation of policies, procedures, methodology o Automatic reports are sent to ensure archiving deadlines are o System prevents the deletion of any document from an and guidance on the planning and performance of engagements including roles and responsibilities for partners, engagement leaders and other members of the team. • Requirement for each engagement to have a Resources plan • o Establishment of policies and procedures to identify engagements archived audit engagement. Implementation of an ongoing monitoring at engagement level (including Milestones, Hot reviews, Partner/Engagement Leader/Engagement Quality Reviewer involvement, etc.). related estimated number of hours and the expected schedule) • met. Performance of on-going and periodic monitoring activities: (including the types of resources (individual roles, specialists), the that is approved by the partner/engagement leader. to archiving to prevent corrupt or non-functional audit documentation. and professional judgement. • Integrity checks performed on the assembled audit file prior o o Annual review and approval of individual partner's workload. Monitoring of late archiving without valid reasons. that require an engagement quality review and to perform engagement quality reviews. • Requirement to use an audit tool when performing an audit engagement. • Implementation of policies and procedures on consultations including a list of mandatory topics for consultation and list of individuals responding to consultations by topics and industry that are selected based on their knowledge, seniority end experience. • Implementation of a policy setting the steps to resolve differences of opinion within the engagement team, or between the engagement team and the Engagement Quality Reviewer. • Implementation of policies on file assembly date and retention. • Setting up of IT controls on the audit and archiving tools: o Engagement documentation is protected by security access during engagement performance and when archived. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 19/27  3.3.5. Resources component 3.3.5.1. Human Resources      Establishment of an evaluation process including: (including commitment o the setting of individual objectives to achieve based on o the annual evaluation based on agreed objectives. Setting up of a process to assign individuals to perform Performance of on-going and periodic monitoring activities: o process for new joiners. criteria competence, Setting up of an annual engagement assignment process for o Organisation of induction trainings as part of the on-boarding evaluation industries, time. requirements are not completed. the assign account their competence and capabilities including sufficient trainings and instructors, and actions to be taken when training o on to leader/Engagement activities within the System of quality management taking into requirements, identification of the audience, selection and pass rates for courses with an assessment, evaluation of depending procedures skills, competencies, availability and permissibility. Implementation of a learning policy including mandatory training of instructors, development of materials, minimum reviewer and engagement teams and specialists taking into account their trainings, continuing professional education, and licensing  partner/engagement potential safeguards should be implemented. Implementation of a recruitment process that involves skilled recruiters and a method for evaluating the candidates.  policies to capabilities, workload and including an evaluation whether Establishment of an annual resource plan that drives the external resources needs.  of engagements Quality recruitment strategy and facilitates the identification of  Establishment to Monitoring of the relevance and reliability of employee’s records. Monitoring of the compliance with continuing professional education and licensing requirements. o Monitoring of the timely completion of mandatory o Monitoring of partner’s and staff workload. trainings. quality). roles. Establishment of a compensation and promotion policy that is 3.3.5.2. Technological Resources • Requirement to use the Audit tool provided by the network. • Identification (list) and ongoing maintenance of the IT systems that enables the firm’s System of quality management. linked to the evaluation process. • Individual evaluation of each IT system relevant for the System of quality management to determine the prioritization and the ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 20/27 frequency, nature and extent of testing on General Information 3.3.6. Information and Communication Technology Controls (GITCs). • Establishment of a procedure to contract with and evaluate service providers used for the development and support of component • relevant information that enables and supports decisions technological resources. • regarding the System of quality management. Development of trainings and practical guidance for end-users to facilitate the use of technological resources and • to questions or issues encountered. Performance of on-going and periodic monitoring activities: o Annual review of technological resources used by the o Monitoring of the effectiveness of GITCs on the firm’s IT fulfil the respective responsibilities relating to • Definition of communication channels and mechanisms within the firm for distributing resources and to report noncompliance. • Preparation of an annual Transparency Report that is approved and published on the firm’s website. 3.3.5.3. • Intellectual Resources Creation of an approved list of intellectual resources (from network, locally developed, from service providers, and legal and regulatory resources), which is made available to personnel and the use of which is actively promoted. • Implementation of a process to maintain the resources up-todate and to update the training materials accordingly. • Establishment of a procedure to contract with and evaluate service providers used for the development and support of intellectual resources. ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 the requirements or services used. firm in terms of relevance and reliability. environment. Establishment of processes to facilitate two-way communication with the network, network firms and service providers in order implementation of a system (call center, ticket) for IT related • Implementation of a process owner’s assessment of the 21/27 3.4. Observations related to the mandatory responses statements of listed entities must be subject to an engagement quality review in accordance with ISQM2 “Engagement Quality Reviews”. 3.4.2. Required responses in the Luxembourg 3.4.1. Specified responses in ISQM 1 In general, the specified responses in ISQM 1 have been included by the firms when designing and implementing responses. Some firms have even refined the granularity of their quality risks to take account of some of these responses. Regarding paragraph 34 (c), several firms, in their implemented responses, have limited complaints and allegations to ethical and behavioural failures reported through dedicated channels. The CSSF would like to point out that the Standard is broader and encompasses “failures to perform work in accordance with professional standards and supplement to ISQM 1 This aspect is clearly an area for improvement for most of the firms inspected in 2023, mainly network member firms, as the requirements were not included in the risk assessment matrix/tool provided by the network and the firms did not complete this reconciliation. The CSSF expects firms to integrate these responses into their risk assessment process and to ensure that the related quality risks have been identified and assessed, but also that firms ensure that theses responses have been implemented when applicable. applicable legal and regulatory requirements or non-compliance with firm’s policies or procedures established in accordance with ISQM”. This point should also be read in conjunction with article 25
(6)of the Audit Law, CSSF Regulation N° 16-07 relating to out-of-court complaint resolution (Section 2) and Circular CSSF 19/717 (Section 1.6). The CSSF would also like to draw firms’ attention to paragraph 34 (f), which should be read in conjunction with the definition of listed entity 5 (which will be superseded at the end of 2024 by the definition of publicly traded entity 6). The CSSF reminds firms that audits of the financial « Listed Entity »: In Luxembourg, it means entities governed by the Luxembourg law whose transferable securities are admitted to trading on a recognized market. (effective for audits of financial statements for period beginning before December 15, 2024). 5 ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 « Publicly traded entity »: In Luxembourg, it means entities governed by the Luxembourg law whose transferable securities are admitted to trading on a regulated market as defined in the MIFID Directive, as well as any other regulated, recognized market open to the public that operates regularly. (effective for audits of financial statements for period beginning on or after December 15, 2024). 6 22/27
  1. Assessment of the design and implementation of the requirements of ISQM 1 dealing with Network Requirements or Network Services 4.
  2. o How the network monitors the appropriateness of the network requirements or network services, which may include through the network firms’ monitoring activities, and the network’s processes for remediating identified deficiencies. Based on this understanding the firm is required to 8: • ISQM 1 requirements analysis relevant to, and are considered in, the firm’s system of quality The postulate of the Standard is that the firm is responsible for its own management, including how they are to be implemented, system of quality management. • firm to be appropriate for use in its system of quality used in the system of quality management, the firm shall understand management. them and their impact on the firm’s system of quality management, but firm the network services or network requirements
  3.  such as: implementing undertaken and, if by the applicable, network in designing, operating, the network requirements or network services, o How the network identifies and responds to changes that affect the network requirements or network services or other information, such as changes in the professional standards or information that indicates a deficiency in the network requirements or network services, drive network may need to adapt and supplement the network This evaluation shall be specifically documented. 9 Monitoring activities: The network may perform monitoring activities across the network firms
  4. The nature, timing and extent of these monitoring activities varies across networks and may also vary from year to year within a network. When the network performs monitoring activities of the firm’s system of quality management, the firm is expected to: 7 ISQM 1 par. 48 and A177 9 8 ISQM 1 par. 49 10 ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 may performs. inquiries of, or documentation provided by the network about matters procedures network the nature and circumstances of the firm and engagements it network requirements or network services. It may be obtained through The the requirements or network services so that they are appropriate for The Standard provides guidance on how the firm can understand the o Although requirements to promote consistent quality across a network, the also its responsibilities for any actions that are necessary to implement The network’s governance and leadership, Evaluate whether and, if so, how the network requirements or network services need to be adapted or supplemented by the As a result, to place reliance on network requirements or network services o Determine how the network requirements or network services are ISQM 1 par. 59 ISQM 1 par. 50 23/27 • • • Determine the effect of the monitoring activities performed 1) Identification of the network requirements/resources and/or by the network on the nature, timing and extent of the firm’s network services that supports the different business processes monitoring activities, within the system of quality management and/or the performance Determine the firm’s responsibilities in relation to the of engagement, monitoring activities, including any related actions by the 2) Understanding, and documentation of the firm, relevance of the network requirements and the network services As part of evaluating findings and identifying deficiencies, for the different business processes 12 and endorsement of the obtain the results of the monitoring activities from the network in a timely manner. responsibility to implement those, 3) Evaluation of the need to adapt and supplement the network requirements/resources/services at local level and documentation Documentation: The documentation related to network requirements or network services may vary based on several factors, including: • The nature of the network requirement or network service, • The documentation provided by the network in relation to the network requirement or network service, and whether it is at a sufficient level of detail to fulfil the requirements of the Standard . However, the firm is responsible for its system of 11 quality management, and therefore is also responsible for the documentation. 4.
  5. determination CSSF expected implementation of the requirements The CSSF has identified several steps that it expects audit firms that are of this evaluation, 4) Monitoring by the firm of the dedicated responses: this could include obtaining agreed upon/specified procedures reports on the testing of the responses by the network with the findings identified, corrective and remedial measures. It could also be controls that the local firm performs over the use of network resources, 5) Evaluating the findings communicated through the report in combination with additional findings at local level or with compensating controls within the firm, to determine whether there are deficiencies, 6) Communication of results of monitoring activities to engagement teams and other individuals that have been assigned responsibilities within the system of quality management for appropriate action. member of a network to implement and document when dealing with network requirements or network services: 11 ISQM 1 par. 58 and 59 That implies for the local firm, identification and assessment of quality risks of using the network requirements/resources/services and design and operation of 12 ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 the responses (with identification of the responsible of the responses (local firm, network resource owner, service model…)) to mitigate the quality risks and documentation of the risk assessment process. 24/27
  6. Conclusion and next steps Quality is not just a matter of compliance, but an essential pillar for the remediation process and the first evaluation of the system of quality management. sustainability of the audit profession. Implementing the requirements of ISQM 1 is part of the process to act in the public interest and to enhance the role of the audit profession for the credibility of the financial reporting ecosystem. There are many benefits to be expected from implementing the Standard: o Creation of a culture of quality, a mindset, a way of being that o A proactive approach to quality management rather that a is integrated into day-to-day operations, reactive approach, with the identification of the root causes for deficiencies and the mitigation of risk of them happening again, that drives continuous improvement, o The components and objectives defined by the Standard provide clear goals that need to be achieved, o The approach is risk-based with tailored and focused responses o Enhanced communication with stakeholders. rather than to comply with a checklist of controls, During the 2023 inspection campaign, the CSSF has focused its work on the risk assessment process and the design and implementation of responses. As identified in the various sections of this report, there are points to monitor and areas for improvement on which the CSSF will focus in the coming months. In the 2024 inspection campaign, the CSSF will continue this work for other firms that are on the scope of the year’s inspections. For firms that are reviewed on an annual basis or every 3 years, the work programme will also include the review of the operating effectiveness of the responses for selected components, the assessment of the monitoring and ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 25/27 Image Resources: Freepik.com, Depositphotos.com ISQM 1 IMPLEMENTATION THEMATIC REPORT Publication date: January 2024 26/27

🔗 Vers la source officielle

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.