Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Does Your Audit Committee Know What QC 1000 Requires?Board Committees and Governance
5 min readFor Board Members and Corporate Secretaries

Does Your Audit Committee Know What QC 1000 Requires?

The PCAOB has shifted its focus from engagement-level deficiencies to systems-level quality control oversight, altering the questions audit committees must ask their external auditors. If your oversight still centers on past audit findings rather than the firm's risk-based quality control framework, you're using an outdated approach.

This checklist translates the PCAOB's evolving strategic priorities into actionable responsibilities for audit committees. It covers three core areas: understanding and evaluating QC 1000 implementation, engaging with emerging risks affecting audit quality, and establishing productive dialogue with the PCAOB and your auditor about systemic quality control.

Checklist Overview

The PCAOB emphasizes that audit quality relies on a shared commitment across the financial reporting ecosystem. This checklist helps audit committees fulfill their role by:

  • Evaluating how your external auditor implements QC 1000's risk-based quality control requirements.
  • Incorporating oversight of emerging risks (technology, AI, cybersecurity) into audit committee responsibilities.
  • Establishing channels for meaningful engagement with the PCAOB and your audit firm on systemic quality matters.

Use this as a quarterly or annual review tool, not a one-time exercise. The PCAOB's modernized inspection approach means your auditor's quality control systems will face ongoing scrutiny, and your oversight must evolve accordingly.

Prerequisites

Before using this checklist, ensure you have:

  • Access to your audit firm's most recent PCAOB inspection report. This provides baseline visibility into how the PCAOB evaluates your auditor's quality control systems.
  • A standing agenda slot for quality control discussions. Regular, scheduled discussions are necessary. Block recurring time to discuss systemic quality matters, separate from engagement-specific audit results.
  • Direct access to the engagement partner and the firm's quality control leadership. QC 1000 conversations require input from both the team executing your audit and the firm-level personnel designing quality control systems.

Checklist Items

Understanding QC 1000 Implementation

1. Obtain a written summary of how your audit firm has implemented QC 1000's risk-based approach.

Request documentation that explains how the firm identifies, assesses, monitors, and remediates risks to audit quality. This focuses on the firm's overall system, not your specific engagement.

2. Confirm the firm has identified quality risks specific to your industry, business model, and audit complexity.

QC 1000 requires risk-based quality control, meaning generic frameworks won't suffice. The firm should articulate quality risks tied to your organization's specific characteristics and explain how its quality control system addresses each.

3. Review the firm's quality response design for risks affecting your audit.

For each identified quality risk, the firm should have designed specific responses. You should be able to trace a direct line from identified risks to the firm's responses and monitoring activities.

4. Ask how the firm monitors the effectiveness of its quality control system.

QC 1000 requires continuous evaluation of quality responses. The firm should describe specific metrics it tracks and explain how monitoring results trigger system improvements.

5. Understand the firm's process for remediating quality control deficiencies.

When monitoring reveals gaps, firms must take corrective action. The firm should provide examples of identified weaknesses, root cause analysis, and systemic changes implemented.

Overseeing Emerging Risks

6. Confirm your audit committee charter explicitly assigns responsibility for oversight of AI and technology risks affecting financial reporting.

Your charter should reflect the reality of AI oversight responsibilities. It should specifically name AI, automation, and emerging technology as audit committee oversight areas.

7. Establish a process for the external auditor to brief you on how they audit AI-driven or automated financial reporting processes.

As your organization adopts new technologies, your auditor must adapt their approach. Annual presentations should explain how they test automated controls and validate AI model outputs.

8. Request the auditor's assessment of cybersecurity risks that could affect financial statement integrity.

Cybersecurity is a financial reporting risk. The auditor should provide a written assessment of how cybersecurity incidents could impact financial statement accuracy and what controls they test.

9. Verify the auditor has access to appropriate specialists for emerging risk areas.

Complex technology and business models require specialized expertise. The firm should demonstrate it has specialists with relevant credentials and explain when and how these specialists get involved in your audit.

Engaging with the PCAOB and Your Auditor

10. Schedule an annual discussion with your auditor about PCAOB inspection findings and their implications for your audit.

The PCAOB's modernized inspection approach emphasizes systemic quality control. Your engagement partner should present the firm's most recent inspection report and describe how remediation efforts affect your audit.

11. Participate in PCAOB outreach opportunities when offered.

The PCAOB emphasizes stakeholder engagement. At least one audit committee member should attend PCAOB webinars, forums, or listening sessions annually and report key takeaways to the full committee.

12. Document your audit committee's perspective on what PCAOB communications and insights would most enhance your oversight.

The PCAOB is committed to making communications more transparent and useful. Your committee should draft a brief memo identifying areas where additional PCAOB guidance would strengthen your oversight.

Common Mistakes

Treating QC 1000 as the auditor's problem alone. Quality control is a shared responsibility. Audit committees that view QC 1000 as purely internal firm business miss the opportunity to strengthen oversight.

Confusing engagement-specific findings with systemic quality control issues. A deficiency in your audit doesn't automatically signal a firm-wide quality control failure. You need visibility into both levels.

Waiting for the PCAOB to mandate new oversight responsibilities. Proactive committees address emerging risks before they become compliance mandates.

Failing to document quality control discussions. When PCAOB inspectors review your auditor, they may examine the firm's communications with audit committees. Undocumented conversations create gaps in the audit trail.

Next Steps

Schedule a dedicated session (minimum 90 minutes) with your external auditor focused exclusively on QC 1000 implementation and emerging risks. Use this checklist as your agenda, and request written responses to items 1-5 at least two weeks before the meeting.

Review your audit committee charter against items 6 and 12. If your charter doesn't explicitly address AI, technology risks, or PCAOB engagement, propose amendments at your next board meeting.

Identify one PCAOB engagement opportunity (webinar, forum, or public comment period) to participate in during the next 12 months. The PCAOB's strategic planning process creates multiple entry points for audit committee input.

Finally, establish a recurring annual agenda item titled "Quality Control Systems Review" separate from your standard audit results discussion. This signals to your auditor that you're evaluating their firm-wide approach to quality, not just your engagement outcomes.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like