Independence, Quality Management, and Regulatory Expectations
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 9 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Apply ISQM 1 to AI tools used in engagements, including the resources and monitoring components most firms overlook
- Meet the engagement partner responsibilities under ISA 220 (Revised) where AI-assisted procedures are used
- Identify the self-review and management-responsibility threats that arise when a firm sells or builds AI tools for its audit clients
- Anticipate the questions inspection teams are asking about AI-assisted work and hold a file to that standard before it is inspected
Everything so far has concerned the engagement. This lesson concerns the system around it — the firm-level obligations that determine whether AI-assisted work is defensible at all, and the independence traps that arise when firms build and sell the tools their audit clients use.
ISQM 1: Tools Are Resources
ISQM 1 requires a firm to design and operate a system of quality management addressing eight components. Three carry most of the weight for AI tools, and one is almost always underdone.
Resources. The standard requires the firm to obtain, develop, use, and maintain appropriate technological resources. That means a firm cannot simply buy a tool and let teams use it. It must evaluate the tool as fit for its intended purpose, define what it may and may not be used for, ensure teams have the competence to use it properly, and maintain it as it changes.
Defining the permitted use is the part most often skipped. A tool approved for directing attention should not be relied on for substantive assurance, and if the firm has not said so, engagement teams will make that judgment individually and inconsistently — which is exactly the inconsistency ISQM 1 exists to prevent.
Engagement performance. Methodology must specify how AI-assisted procedures are performed, documented, and reviewed. Standard working paper templates for full-population testing, mandatory reconciliation steps, and required review questions all sit here, and they are far more effective than training alone because they make the right approach the default.
Monitoring and remediation. This is the underdone component. Firms monitor engagement quality through file reviews, but AI tool performance is a firm-level property that file review is poorly suited to detect. If a routine has a systematic flaw, every file using it looks internally consistent and complete, and reviewing more files will not surface the problem — the flaw is uniform. Detecting it requires monitoring the tool itself: periodic revalidation, seeded-error testing at firm level, and analysis of whether results across engagements look plausible in aggregate. A routine that returns zero exceptions across forty engagements is a firm-level signal that no individual file review would raise.
A systematic defect in a firm-wide routine is invisible to file review because it affects every file identically and consistently. Firm-level monitoring of tool performance is the only control positioned to detect it, and it is the component most commonly missing from a firm quality management response to AI.
ISA 220 (Revised): The Partner Cannot Delegate Understanding
ISA 220 (Revised) makes the engagement partner responsible for managing and achieving quality on the engagement, including that sufficient appropriate resources are used and that the direction, supervision, and review performed is sufficient given the circumstances.
Applied to AI-assisted procedures this has a specific implication: a partner cannot sign an engagement where the assurance rests on a procedure nobody on the team can explain. The partner does not need to understand the mathematics. They do need to be able to state what the procedure tested, what assertion it addressed, what population it covered, and what its limitations are — which is precisely the content lesson one required in the working paper.
Where a firm-approved tool is used, the partner is entitled to rely on the firm's evaluation of the tool for tool-level matters. They cannot rely on it for engagement-level matters, because the firm's approval says nothing about whether the extract for this client was complete or the criteria appropriate to this entity's risks. That distinction, from lesson five, is where partner responsibility actually bites.
Direction and supervision also need adjusting. A team member running a routine they do not understand, on a population they did not reconcile, is not performing an audit procedure in any meaningful sense, and the supervision failure belongs to the engagement leadership rather than to them.
Independence: Self-Review and Management Responsibility
Firms increasingly build AI tools and sell or license them, and this creates threats that the traditional independence framework covers but that are easy to miss because they arrive dressed as technology.
Self-review. If the firm provides an AI tool to an audit client and that tool produces or processes information affecting the financial statements, auditing that output means auditing the results of the firm's own service. A tool licensed to a client for lease classification, contract extraction, or estimate calculation, whose output feeds the financial statements, creates a self-review threat directly.
Management responsibility. If the firm configures, tunes, or operates a system that determines an amount in the financial statements, the firm risks assuming a management responsibility. Setting the parameters that drive a client's expected credit loss model is participating in management decision-making, whatever the engagement letter calls it.
Advocacy and familiarity. A firm with a commercial interest in a client adopting its platform has an interest in that adoption being seen to succeed, which is uncomfortable when auditing the outputs.
The analysis is ordinary: identify the threat, evaluate significance, apply safeguards or decline. What is new is remembering to perform it at all. A tool licence is often handled as a procurement matter between the client and the firm's technology arm, without ever reaching the independence assessment for the audit engagement. The practical safeguard is a firm-level requirement that any technology arrangement with an audit client is routed through independence review before it is agreed, with the specific question being whether the tool's output touches the financial statements.
An audit firm licenses its own contract analysis platform to an audit client. The client uses it to extract lease commencement dates and payment terms, which feed directly into the IFRS 16 lease liability calculation in the financial statements. The audit team plans to test the lease liability by examining the platform's extracted data. What is the principal independence issue?
Select one answer.
What Inspectors Are Asking
Audit regulators — the PCAOB in the United States, the FRC in the United Kingdom, and their equivalents elsewhere — have moved from general interest in firms' use of technology to specific file-level questions. The IAASB has also been working on how the ISAs accommodate technology-assisted procedures, and the direction of travel is consistently towards more explicit documentation rather than less.
The questions being asked at file level are the ones this course has built towards:
- What was the population, and how did you establish it was complete?
- What exactly did the routine test, and which assertion does that address?
- Where did the threshold or criteria come from, and how do they relate to performance materiality?
- What is your basis for concluding on the items the routine did not flag?
- How do you know the routine works — what testing supports that?
- Who reviewed this, and what did the review consist of?
None of these is unreasonable and none is new in principle. They are the ordinary evidence and documentation questions applied to a procedure whose mechanics are less visible. A file that can answer all six is in good shape regardless of how the regulatory guidance develops; a file that can answer none is exposed even if the underlying work was excellent.
The most useful firm-level habit is to apply these six questions as a pre-issuance review step on any engagement placing significant reliance on an AI-assisted procedure. It costs an hour and it is the difference between finding the gap yourself and having it found for you.
Forty clean files, one firm-level flaw, found by monitoring rather than by file review
Context
A firm deployed a standardised revenue completeness routine across its audit portfolio. Over an eighteen-month period it was used on 41 engagements. File reviews on a sample of twelve engagements raised no issues: each file documented the routine, the population, and the results consistently and in line with methodology.
Action
As part of building out the monitoring component of its ISQM 1 response, the quality team began analysing tool outputs in aggregate across engagements rather than file by file. The revenue completeness routine had returned zero exceptions on 38 of 41 engagements. The team judged that implausible across a portfolio of that size and diversity, and commissioned seeded-error testing: realistic cut-off misstatements at performance materiality were introduced into a copy of three client datasets and the routine was re-run. It detected none of them, because a date comparison in the routine used the posting date rather than the despatch date, making genuine cut-off errors invisible by construction.
Outcome
The routine was corrected and re-run across all engagements still within their retention window; four engagements required additional procedures and one required a restatement of prior year comparatives. The head of audit quality noted that twelve individual file reviews had found nothing because there was nothing wrong with any individual file — the flaw was uniform, so consistency across files looked like quality rather than like a symptom. The firm added mandatory annual seeded-error testing for every firm-wide routine and aggregate output analysis as a standing monitoring procedure.
Twelve file reviews across engagements using the defective revenue completeness routine raised nothing at all. Why does this lesson say file review was never positioned to find the defect?
Select one answer.
Exercise
Your Task
Take one AI or analytics tool your firm uses in audit engagements and assess it against the three ISQM 1 components in this lesson. For resources: has the firm defined what the tool may and may not be used for, specifically whether it may support substantive assurance or only direct attention? For engagement performance: does methodology specify required steps such as population reconciliation and two-directional reperformance? For monitoring: is there any firm-level testing of the tool itself, as distinct from review of files that used it? Then apply the six inspection questions to one file that used the tool, and record which you cannot answer from the file alone.
Success looks like
- The permitted-use question is answered specifically, distinguishing substantive reliance from attention direction
- Firm-level tool monitoring is assessed separately from engagement file review, recognising they detect different failures
- The six inspection questions are answered strictly from the file, with gaps recorded honestly
- Any technology arrangement with an audit client is checked against whether its output touches the financial statements
Watch out for
- Treating file review as sufficient monitoring of a firm-wide routine, when a uniform defect makes every file look consistent
- Handling a tool licence to an audit client as procurement without routing it through independence review
- Under ISQM 1, AI tools are technological resources the firm must evaluate, define permitted uses for, and maintain. Failing to state whether a tool may support substantive assurance or only direct attention leaves that judgment to individual teams.
- Firm-level monitoring is the component most often missing and the only one positioned to catch a systematic routine defect, because a uniform flaw makes every individual file look internally consistent and complete.
- ISA 220 (Revised) means a partner cannot sign an engagement whose assurance rests on a procedure nobody can explain. Firm tool approval covers tool-level matters only; population completeness and criteria appropriateness remain engagement-level partner responsibilities.
- Firms selling or licensing AI tools to audit clients create self-review and management-responsibility threats whenever the output touches the financial statements. The common failure is that the arrangement is handled as procurement and never reaches independence review.
- Inspection is converging on six file-level questions covering population completeness, what was tested and which assertion, threshold derivation, the basis for unflagged items, evidence the routine works, and the nature of review. Applying them as a pre-issuance step is the cheapest way to find gaps first.