SQM 1 Quality Management explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
SQM 1 asks an audit firm to manage quality as a set of risks: decide what good quality means, find what could go wrong, and build responses. This first part covers the eight components and the requirements up to specified responses.
SQM 1, as effective for systems of quality management designed and implemented by 1 April 2025 on a recommendatory basis, with a mandatory date of 1 April 2026 that has been deferred, is not yet mandatory. ICAI may revise standards, so check icai.org for the current text.
SQM 1 requires a firm to design, implement and operate a system of quality management built on eight components and a risk-based approach: set quality objectives, identify and assess quality risks, and design responses. The firm's head carries ultimate responsibility and must evaluate the system at least annually. ICAI's Council deferred the mandatory date of SQM 1 and SQM 2 on 31 March 2026 "until further announcement", so SQC 1 still applies and SQM 1 may be applied on a recommendatory basis.
Status: what applies today
The text of SQM 1 prints two effective-date paragraphs. The recommendatory one (paragraph 13) says systems should be designed and implemented by 1 April 2025, with the first evaluation within one year of that date. The mandatory one repeats this with 1 April 2026. On 31 March 2026 ICAI announced that the mandatory date was deferred until further announcement and that the existing SQC 1 continues to apply. So a firm may move to SQM 1 now, but it is not required to, and SQM 1 has not replaced SQC 1.
Scope and approach (paragraphs 1-12)
SQM 1 deals with a firm's responsibility to design, implement and operate a system of quality management for audits or reviews of financial statements, or other assurance or related services engagements. It applies to every firm that performs any of those engagements (paragraph 5). Engagement quality reviews are part of the system; SQM 1 requires the firm to have policies on which engagements get one, and SQM 2 governs the reviewer and the review.
The system works in a "continual and iterative" way, not as a straight line (paragraph 6). The risk-based approach has three steps (paragraph 8): set quality objectives, identify and assess quality risks, and design and implement responses that fit the reasons for the risk assessment. Paragraph 10 introduces scalability: a firm auditing listed entities will need a more formal system than one that only does reviews or compilations. Paragraph 11 says a firm that uses network requirements, network services or a service provider is still responsible for its own system.
The objective (paragraph 14) is reasonable assurance that the firm and its people meet professional standards and legal requirements, and that reports are appropriate in the circumstances.
The eight components
| Component | Paragraph | Closest SQC 1 element |
|---|---|---|
| Risk assessment process | 23-27 | No direct equivalent; new |
| Governance and leadership | 28 | Leadership responsibilities for quality |
| Relevant ethical requirements | 29 | Ethical requirements, including independence |
| Acceptance and continuance | 30 | Acceptance and continuance |
| Engagement performance | 31 | Engagement performance |
| Resources | 32 | Human resources, widened to technology, intellectual resources and service providers |
| Information and communication | 33 | No direct equivalent; new |
| Monitoring and remediation | 35-47 | Monitoring; see part 2 |
Key terms in plain words
| Term (paragraph 16) | Meaning |
|---|---|
| Quality objectives | The outcomes the firm wants in each component |
| Quality risk | A risk with a reasonable possibility of occurring and of adversely affecting one or more quality objectives |
| Response | A policy (what should or should not be done) or procedure (action to carry it out) that addresses a quality risk |
| Deficiency | A missing objective, an unidentified or wrongly assessed risk, a response that does not reduce the risk enough, or another gap in meeting the standard |
| Findings | Information from monitoring, external inspections or other sources that indicates a deficiency may exist |
Applying the standard and assigning roles (paragraphs 17-22)
A firm complies with every requirement unless it is not relevant to the firm's nature and circumstances (paragraph 17). The people with ultimate and operational responsibility must understand SQM 1 including the application material (paragraph 18).
Paragraph 20 requires three assignments: ultimate responsibility and accountability to the chief executive, managing partner or managing board of partners; operational responsibility for the system; and operational responsibility for compliance with independence and for the monitoring and remediation process. Each person needs experience, knowledge, influence, authority and time, and a direct line of communication to the head of the firm (paragraphs 21-22). In a small firm the same partner may hold more than one role, provided that person has the time and authority.
The risk assessment process (paragraphs 23-27)
The firm sets the quality objectives that SQM 1 specifies plus any others it needs (paragraph 24). It then identifies quality risks by understanding what could affect the objectives (paragraph 25), looking at the firm itself and at its engagements:
- the firm's complexity and operating characteristics, business model, leadership style, resources including service providers, the law and professional environment, and network requirements;
- the types of engagements, the reports it issues and the types of entities it audits.
Responses must fit the reasons for each assessment (paragraph 26). The firm also needs a way to spot changes that call for new objectives, risks or responses, and must update the system when they appear (paragraph 27).
Governance and leadership (paragraph 28)
The quality objectives here cover a culture of commitment to quality, including the firm's public interest role, professional ethics and each person's responsibility; leadership that is accountable and demonstrates commitment by its actions; a suitable structure and assignment of roles; and planning and allocating resources, including financial resources, consistent with that commitment.
Ethics, acceptance and engagement performance (paragraphs 29-31)
- Ethics. The firm, its personnel, and others such as the network and service providers understand and fulfil the relevant ethical requirements, including independence (paragraph 29).
- Acceptance and continuance. Decisions rest on sufficient information about the nature of the engagement and the integrity and ethical values of the client, and on the firm's ability to perform the work. The firm's own financial and operational priorities must not lead to inappropriate decisions (paragraph 30).
- Engagement performance. Teams understand their duties, including the engagement partner's overall responsibility for quality; direction, supervision and review fit the engagement; teams use judgment and skepticism; difficult matters are consulted on; differences of opinion are resolved; and documentation is assembled on time and retained (paragraph 31).
Resources, information and specified responses (paragraphs 32-34)
Resources cover people, technology, intellectual resources and service providers (paragraph 32). The firm must make sure that individuals with competence and capabilities are hired, developed and held accountable, that engagement teams and the partner are given enough time, and that technology and intellectual resources used by the firm are suitable. Information and communication (paragraph 33) require a reliable information system, a culture of exchanging information, and communication with the network, service providers and external parties when required.
Paragraph 34 lists responses every firm must include, whatever its risk assessment says:
- Policies on threats to and breaches of ethical requirements.
- A documented independence confirmation, at least annually, from all personnel required to be independent.
- A process to receive, investigate and resolve complaints and allegations.
- Policies for situations where the firm learns something that would have made it decline a client, or is obliged by law to accept one.
- Policies on communication with those charged with governance for listed entity audits and with external parties.
- An engagement quality review for listed entity audits, for engagements where law requires one, and where the firm decides one is an appropriate response to a quality risk.
Illustrative example
Verma Associates, an invented four-partner firm, audits two listed entities and several private companies. In its risk assessment it notes that a key partner is retiring, that audit software is shared across offices, and that listed audits are concentrated in one industry. It sets a quality objective on competence, identifies the loss of industry expertise as a quality risk, and responds by assigning a second partner to shadow the listed audits and by requiring an engagement quality review on both listed audits.
Need help with firm-level quality?
If your firm is thinking through its quality objectives, risks and responses, TaxClue's compliance advisory team can help you map them in a way that suits your practice. Audited companies can also use our compliance advisory support to understand what auditors are now documenting.
Key takeaways
- SQM 1 uses objectives, risks and responses across eight components.
- The head of the firm holds ultimate responsibility and evaluates the system at least annually.
- The mandatory date was deferred on 31 March 2026; SQC 1 applies and SQM 1 is recommendatory.
- Some responses are specified for every firm, including annual independence confirmations and an engagement quality review for listed entity audits.
- A network or service provider does not take away the firm's own responsibility.
Read next
- SQM 1, part 2: monitoring, remediation and evaluation
- SQC 1, part 1: the system that applies today
- SQM 2: engagement quality reviews
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
