Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026tomorrow 11 OCTGSTR-1 · Outward supplies · Sep 2026in 5 days 15 OCTPF & ESI · Contributions · Sep 2026in 9 days 20 OCTGSTR-3B · Summary return · Sep 2026in 14 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 15 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 24 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 46 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 54 days
All due dates

SQM 1, Quality Management for Firms that Perform Audits or Reviews of Financial Statements, or Other Assurance or Related Services Engagements (part 1 of 2): the eight components, risk assessment, governance and resources

SQM 1 requires a firm to design, implement and operate a system of quality management built on eight components and a risk-based approach: set quality objectives, identify and...

Published
Updated
Reading time
9 min
Views
11
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 3, 2026
Last updated
Oct 6, 2026
Reading time
9 min
0:00
Last updated: October 2026Verified against: Government sources

SQM 1 asks an audit firm to manage quality as a set of risks: decide what good quality means, find what could go wrong, and build responses. This first part covers the eight components and the requirements up to specified responses.

SQM 1, as effective for systems of quality management designed and implemented by 1 April 2025 on a recommendatory basis, with a mandatory date of 1 April 2026 that has been deferred, is not yet mandatory. ICAI may revise standards, so check icai.org for the current text.

Status: what applies today

The text of SQM 1 prints two effective-date paragraphs. The recommendatory one (paragraph 13) says systems should be designed and implemented by 1 April 2025, with the first evaluation within one year of that date. The mandatory one repeats this with 1 April 2026. On 31 March 2026 ICAI announced that the mandatory date was deferred until further announcement and that the existing SQC 1 continues to apply. So a firm may move to SQM 1 now, but it is not required to, and SQM 1 has not replaced SQC 1.

Scope and approach (paragraphs 1-12)

SQM 1 deals with a firm's responsibility to design, implement and operate a system of quality management for audits or reviews of financial statements, or other assurance or related services engagements. It applies to every firm that performs any of those engagements (paragraph 5). Engagement quality reviews are part of the system; SQM 1 requires the firm to have policies on which engagements get one, and SQM 2 governs the reviewer and the review.

The system works in a "continual and iterative" way, not as a straight line (paragraph 6). The risk-based approach has three steps (paragraph 8): set quality objectives, identify and assess quality risks, and design and implement responses that fit the reasons for the risk assessment. Paragraph 10 introduces scalability: a firm auditing listed entities will need a more formal system than one that only does reviews or compilations. Paragraph 11 says a firm that uses network requirements, network services or a service provider is still responsible for its own system.

The objective (paragraph 14) is reasonable assurance that the firm and its people meet professional standards and legal requirements, and that reports are appropriate in the circumstances.

The eight components

ComponentParagraphClosest SQC 1 element
Risk assessment process23-27No direct equivalent; new
Governance and leadership28Leadership responsibilities for quality
Relevant ethical requirements29Ethical requirements, including independence
Acceptance and continuance30Acceptance and continuance
Engagement performance31Engagement performance
Resources32Human resources, widened to technology, intellectual resources and service providers
Information and communication33No direct equivalent; new
Monitoring and remediation35-47Monitoring; see part 2

Key terms in plain words

Term (paragraph 16)Meaning
Quality objectivesThe outcomes the firm wants in each component
Quality riskA risk with a reasonable possibility of occurring and of adversely affecting one or more quality objectives
ResponseA policy (what should or should not be done) or procedure (action to carry it out) that addresses a quality risk
DeficiencyA missing objective, an unidentified or wrongly assessed risk, a response that does not reduce the risk enough, or another gap in meeting the standard
FindingsInformation from monitoring, external inspections or other sources that indicates a deficiency may exist

Applying the standard and assigning roles (paragraphs 17-22)

A firm complies with every requirement unless it is not relevant to the firm's nature and circumstances (paragraph 17). The people with ultimate and operational responsibility must understand SQM 1 including the application material (paragraph 18).

Paragraph 20 requires three assignments: ultimate responsibility and accountability to the chief executive, managing partner or managing board of partners; operational responsibility for the system; and operational responsibility for compliance with independence and for the monitoring and remediation process. Each person needs experience, knowledge, influence, authority and time, and a direct line of communication to the head of the firm (paragraphs 21-22). In a small firm the same partner may hold more than one role, provided that person has the time and authority.

The risk assessment process (paragraphs 23-27)

The firm sets the quality objectives that SQM 1 specifies plus any others it needs (paragraph 24). It then identifies quality risks by understanding what could affect the objectives (paragraph 25), looking at the firm itself and at its engagements:

  • the firm's complexity and operating characteristics, business model, leadership style, resources including service providers, the law and professional environment, and network requirements;
  • the types of engagements, the reports it issues and the types of entities it audits.

Responses must fit the reasons for each assessment (paragraph 26). The firm also needs a way to spot changes that call for new objectives, risks or responses, and must update the system when they appear (paragraph 27).

Governance and leadership (paragraph 28)

The quality objectives here cover a culture of commitment to quality, including the firm's public interest role, professional ethics and each person's responsibility; leadership that is accountable and demonstrates commitment by its actions; a suitable structure and assignment of roles; and planning and allocating resources, including financial resources, consistent with that commitment.

Ethics, acceptance and engagement performance (paragraphs 29-31)

  • Ethics. The firm, its personnel, and others such as the network and service providers understand and fulfil the relevant ethical requirements, including independence (paragraph 29).
  • Acceptance and continuance. Decisions rest on sufficient information about the nature of the engagement and the integrity and ethical values of the client, and on the firm's ability to perform the work. The firm's own financial and operational priorities must not lead to inappropriate decisions (paragraph 30).
  • Engagement performance. Teams understand their duties, including the engagement partner's overall responsibility for quality; direction, supervision and review fit the engagement; teams use judgment and skepticism; difficult matters are consulted on; differences of opinion are resolved; and documentation is assembled on time and retained (paragraph 31).

Resources, information and specified responses (paragraphs 32-34)

Resources cover people, technology, intellectual resources and service providers (paragraph 32). The firm must make sure that individuals with competence and capabilities are hired, developed and held accountable, that engagement teams and the partner are given enough time, and that technology and intellectual resources used by the firm are suitable. Information and communication (paragraph 33) require a reliable information system, a culture of exchanging information, and communication with the network, service providers and external parties when required.

Paragraph 34 lists responses every firm must include, whatever its risk assessment says:

  1. Policies on threats to and breaches of ethical requirements.
  2. A documented independence confirmation, at least annually, from all personnel required to be independent.
  3. A process to receive, investigate and resolve complaints and allegations.
  4. Policies for situations where the firm learns something that would have made it decline a client, or is obliged by law to accept one.
  5. Policies on communication with those charged with governance for listed entity audits and with external parties.
  6. An engagement quality review for listed entity audits, for engagements where law requires one, and where the firm decides one is an appropriate response to a quality risk.

Illustrative example

Verma Associates, an invented four-partner firm, audits two listed entities and several private companies. In its risk assessment it notes that a key partner is retiring, that audit software is shared across offices, and that listed audits are concentrated in one industry. It sets a quality objective on competence, identifies the loss of industry expertise as a quality risk, and responds by assigning a second partner to shadow the listed audits and by requiring an engagement quality review on both listed audits.

Need help with firm-level quality?

If your firm is thinking through its quality objectives, risks and responses, TaxClue's compliance advisory team can help you map them in a way that suits your practice. Audited companies can also use our compliance advisory support to understand what auditors are now documenting.

Key takeaways

  • SQM 1 uses objectives, risks and responses across eight components.
  • The head of the firm holds ultimate responsibility and evaluates the system at least annually.
  • The mandatory date was deferred on 31 March 2026; SQC 1 applies and SQM 1 is recommendatory.
  • Some responses are specified for every firm, including annual independence confirmations and an engagement quality review for listed entity audits.
  • A network or service provider does not take away the firm's own responsibility.

Read next

Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SQM 1 Quality Management

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Is SQM 1 mandatory now?

No. ICAI deferred the mandatory date on 31 March 2026 until further announcement, and SQC 1 continues to apply. Firms may apply SQM 1 on a recommendatory basis.

What is a quality risk?

It is a risk with a reasonable possibility of occurring and, alone or with others, adversely affecting a quality objective (paragraph 16).

Books written up every week need no heroics at year end.

— TaxClue Accounts & Audit Desk

SQM 1 Quality Management: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. ICAI deferred the mandatory date on 31 March 2026 until further announcement, and SQC 1 continues to apply. Firms may apply SQM 1 on a recommendatory basis.

It is a risk with a reasonable possibility of occurring and, alone or with others, adversely affecting a quality objective (paragraph 16).

Yes, to any firm performing audits, reviews or other assurance engagements, but the complexity and formality of the system scale with the firm (paragraphs 5 and 10).

Ultimate responsibility sits with the chief executive, managing partner or managing board; operational roles, including independence and monitoring, are assigned separately (paragraph 20).

No. SQM 1 requires one for listed entity audits, where law requires it, and where the firm decides it addresses a quality risk (paragraph 34(f)).

SQC 1 sets policy elements; SQM 1 adds a risk assessment process, an information component and an annual evaluation by the firm's head.