During a recent cold file review, one issue stood out and it’s something we continue to see across many firms, an Engagement Quality Review had been carried out by the Audit Manager rather than someone formally authorised by the firm with the appropriate authority and experience.
It’s a good reminder to step back and revisit what ISQM 2 requires.
What ISQM 2 Says (in simple terms)?
ISQM 2 places responsibility on the firm to establish clear policies on who is eligible to act as an EQR. Those policies must ensure that the reviewer:
- has the experience, competence and authority to challenge the engagement team
- is independent of the engagement
- exercises objectivity and professional scepticism
- has not been involved in making key judgements on the audit
In most UK firms, this typically means:
- RIs / Audit Partners, or
- Senior individuals explicitly authorised by the firm, usually with partner‑level authority and appropriate safeguards.
Why an Audit Manager Is Usually Not Appropriate?
An Audit Manager will often fail one or more of the ISQM 2 criteria:
- Authority: Managers rarely have the standing to challenge partner‑level judgements.
- Independence: They may have been involved in planning discussions, consultations or technical support.
- Objectivity: Being part of the operational delivery structure creates a self‑review threat.
Unless the firm’s SoQM explicitly authorises managers to act as EQRs and sets out how authority, independence and objectivity are safeguarded the appointment will not meet ISQM 2.
In practice, this would require a clear reporting line to an independent RI or partner who is not involved in the engagement, so that any disagreement can be escalated at an equivalent level of authority.
A Practical Example
Scenario:
- A non‑PIE statutory audit requires an EQR under firm policy.
- The Audit Partner signs the audit opinion.
- The Audit Manager from the same office performs the EQR.
Background:
The Manager had previously provided technical input on the planning memo and contributed to a key accounting judgement.
(Simply reviewing the planning memo would not be a problem, EQRs are expected to review planning. The issue arises when the reviewer has participated in planning or key judgements.)
ISQM 2 problem:
- The reviewer has participated in key judgements.
- There is a clear self‑review threat.
- The reviewer does not have equivalent authority to challenge the partner.
Correct approach:
- Appoint an independent RI or partner not involved in the engagement, or
- Use a senior reviewer who has a formal reporting line to an independent RI/partner, with documented eligibility, independence checks and authority within the SoQM.
- Appoint an external audit file reviewer such as HAT to perform the review
Key Takeaway for Firms
ISQM 2 is not about who is available, it is about ensuring robust challenge and audit quality.
Firms should be asking:
- Is our EQR eligibility clearly defined?
- Do our reviewers have genuine authority and independence?
- Would our approach withstand regulator or cold file review scrutiny?
If the answer is anything other than a confident “yes”, the system needs strengthening.
Audit quality isn’t improved by a signature, it’s improved by effective challenge.
