Download Whitepaper

We collaborate with best-in-class platforms, consultants, and technology providers to deliver seamless, future-proof solutions, built to grow with your organization.

How do you build a system of quality management that works under ISQM 1?

Phuong Pham
September 10, 2025
5 min read

ISQM 1 requires audit firms to move from a static quality control model to a dynamic quality management system. But writing a manual is not the same as having a system that works. A true System of Quality Management (SoQM) turns compliance requirements into repeatable processes supported by data, technology, and governance. When done right, it shifts quality from being a cost of compliance to a driver of resilience and trust.

Understanding systems of quality management under ISQM 1

At its core, ISQM 1 asks firms to establish objectives, identify risks that threaten those objectives, implement controls, and monitor whether those controls are effective. This creates a continuous cycle of improvement rather than a once-a-year checklist.

A working SoQM does three things consistently:

  • Captures quality risks where they actually occur—in processes, engagements, and governance.
  • Links risks to clear controls, owners, and evidence.
  • Uses monitoring, incidents, and improvement actions to keep the system alive.

Without this systemic approach, ISQM efforts risk becoming fragmented documents that auditors cannot rely on.

What makes ISQM 1 different from ISQC 1?

Under ISQC 1, firms relied on a prescriptive set of controls. ISQM 1 instead introduces a risk-based approach, requiring every firm—large or small—to tailor its quality objectives and responses to its own size, services, and clients.

This means:

  • No two firms will have identical systems. A boutique audit practice may design leaner processes than a Big Four firm, yet both must show risks are addressed.
  • Both design and operation matter. Controls must be well-designed and proven to work in practice.
  • Continuous monitoring is required. Quality can’t be reviewed once a year; it must be tracked as a living system.

How do you operationalize ISQM 1?

Turning ISQM 1 into practice means creating a repeatable cycle that everyone in the firm understands and follows. Think of it as moving from a static manual to a living system:

  1. Set quality objectives – Start by defining what “quality” really means for your firm. For some, it’s audit efficiency and client trust; for others, it may also include meeting sector-specific regulatory expectations. Clear objectives give direction to everything else.
  1. Identify and assess risks – Consider what could prevent those objectives from being achieved. For example, staff turnover might undermine audit quality, or weak IT access controls could compromise independence. This step ensures risks are tied directly to your firm’s reality.
  1. Design and implement controls – Each risk requires a tailored response. That could mean introducing training requirements, adding peer reviews for high-risk clients, or implementing automated access reviews. Controls should be practical, owned by the right people, and documented.
  1. Monitor and test – ISQM requires not just designing controls, but proving they work. This includes periodic testing, root cause analysis when failures occur, and using incidents as learning opportunities.
  1. Take remedial action – A working SoQM doesn’t hide weaknesses—it improves them. Documenting failures, assigning corrective actions, and tracking whether improvements stick ensures the system matures over time.
Objective based Risk & Quality Management Process
Figure 1: Objective based Risk & Quality Management Process

Technology like CERRIX embeds this cycle into daily workflows, automating reminders for control owners, centralizing evidence, and linking risks, incidents, and improvements together.

What are common mistakes to avoid in ISQM implementation?

Despite good intentions, many firms stumble in similar ways:

  • Treating ISQM as a documentation exercise – Drafting policies may tick a box, but regulators want proof of effectiveness. Without evidence of real control testing, your SoQM won’t stand up to scrutiny.
  • Relying on spreadsheets – Excel may feel easy at first, but it can’t provide version control, audit trails, or workflow accountability. Firms often discover too late that it leaves them exposed during inspections.
  • Overloading the second line of defense – Risk and compliance teams can guide and monitor, but they can’t “own” audit quality. If accountability doesn’t sit with engagement leaders and service line heads, quality won’t be embedded.
  • Failing to link incidents and improvements back to risks – When an inspection finds an error or a control fails, the system must adapt. A true SoQM learns from these signals by updating risks, adjusting controls, and monitoring remediation.

Avoiding these mistakes requires treating ISQM as an ongoing process, not a one-off compliance project.

How do you measure if your system is working?

A system of quality management is only effective if you can demonstrate that it actually improves outcomes. That means defining and tracking metrics that go beyond “compliance checklists”:

  • Control test coverage – Are you testing a representative sample of controls, or just a fraction? Coverage rates show how much assurance you can really place on your system.
  • Exception rates – Look at how often controls fail, are skipped, or are overdue. A high exception rate may point to unrealistic processes or poor ownership.
  • Incident trends – Do incidents repeat? How quickly are they remediated? Root cause analysis should reveal whether weaknesses are one-offs or systemic.
  • KRI/KPI monitoring – Key risk indicators (e.g., staff utilization, independence breaches, overdue file reviews) can provide early warning signals before risks escalate.

The most effective firms consolidate these metrics into a centralized risk & control register. This creates a single source of truth where risks, controls, incidents, and test results are all linked and auditable. Dashboards and drill-down reports then turn the data into actionable insights for partners, risk committees, and regulators. Instead of a static report once a year, firms can continuously demonstrate that quality is not only designed but proven in practice.

Centralized risk and control register in CERRIX with real-time dashboards, risk scoring, and linked incidents for ISQM compliance
Figure 2: CERRIX Risk and Control management workspaces.

Key takeaways for building a SoQM that delivers value

ISQM 1 is not about more paperwork. It’s about creating a living quality system that is risk-based, evidence-driven, and continuously improving. Firms that operationalize ISQM 1 effectively will benefit from:

  • Greater trust from regulators and clients
  • Lower audit risk and remediation costs
  • More efficient processes and less manual burden
  • A culture where quality is owned across the firm, not delegated to compliance

At CERRIX, we help audit firms transform ISQM 1 requirements into an integrated system of quality management. With automated workflows, real-time monitoring, and audit-ready reporting, our platform makes quality measurable and manageable. Watch our on-demand webinar Everything You Need to Know About Implementing ISQM in Audit Firms.

Download your guide for ISQM implementation within Audit firms

Share this post

Related content

Hoe Wij CERRIX GRC Gebruiken voor het Beheren van Ons ISMS. ISO 27001 in de Praktijk

Wij gebruiken onze eigen CERRIX GRC-software om het ISMS van CERRIX te beheren. Zo maken we van compliance een continu proces en laten we zien hoe ISO 27001 onderdeel wordt van de dagelijkse praktijk.

Hoe bereken je risicokans en -impact?

Leer hoe je risicokans en -impact berekent volgens ISO 31000. Ontdek hoe gestructureerde risicobeoordeling, scoringsmodellen en risicomatrices bijdragen aan effectief risicomanagement met CERRIX.

Why the Three Lines of Defense Model Is Outdated? What Every Board Should Know About the Three Lines Model

Three Lines Model Explained: Why Boards Must Move Beyond 3LOD

What Is ISO 31000 and How Does It Work?

Discover what ISO 31000 is, how it works, and why it’s essential for risk management in 2025. Learn the principles, framework, and how tools like CERRIX help organizations turn ISO 31000 into practice.

How to Write an Incident Report That Stands Up to Audits

Learn how to write incident reports that are clear, evidence-backed, and audit-ready. Includes a template, best practices, and compliance alignment for risk professionals.

How to Implement ISO 31000: Real-Time Risk Decisions with AI‑Enabled Tools

Discover how to move beyond compliance and operationalize ISO 31000 using AI, real-time dashboards, and structured risk assessments. Learn from webinar insights and best practices tailored for financial services and regulated industries.

compliance team looking for ISMS

What’s Blocking Your ISMS Rollout? 7 Fixable Challenges for Financial Institutions

Discover the 7 biggest blockers in ISMS rollout for financial institutions—and how to solve them. Learn practical strategies to secure buy-in, define scope, streamline controls, and prepare for ISO 27001 certification.

working compliance manager

Trends Driving ISMS Adoption in 2025: What Risk & Compliance Leaders Need to Know

Discover the top trends pushing organizations toward ISMS adoption in 2025—from regulatory changes and remote work to threat evolution and AI. Learn what to prioritize to stay ahead in risk and compliance.

ISMS

What Is an ISMS? A Practical Guide for Risk & Compliance Leaders in 2025

An Information Security Management System (ISMS) is more than policy—it’s your organization’s shield against evolving threats, regulation, and reputation risk. Discover what ISMS means, how to implement it, and why it matters in 2025.

AI in GRC

The Intelligent Future of GRC: How AI is Reshaping Governance, Risk & Compliance in 2025

Explore how AI is transforming GRC in 2025—from predictive insights and automation to ethical oversight. Learn what features matter, what risks to manage.

How Do You Implement an ISMS in Financial Services Without Slowing Down Innovation?

Implementing an ISMS in financial services? Explore a practical, risk-aligned roadmap tailored for banks, fintechs, and insurers to meet ISO 27001, GDPR, and DORA compliance—without compromising agility.

How Do You Build a Robust ISMS Framework Based on ISO 27001?

Learn how to build a robust ISMS framework aligned with ISO 27001. Discover the key components—people, policies, processes, and controls—to strengthen security and achieve compliance.

When to Conduct Risk Assessments: 6 Enterprise-Critical Moments

Learn when to conduct risk assessments—annual, quarterly, after incidents or change—and how CERRIX ensures continuous compliance.

How do you build a system of quality management that works under ISQM 1?

Learn how to build a system of quality management under ISQM 1. Move beyond compliance to an operational model that proves audit quality.

Top GRC Platforms Compared: Risk Assessment Tools for 2025

Discover the top GRC platforms for 2025 with a focus on risk assessment tools.

What Are Risk Scoring Methods for Financial Institutions? [2025 Guide]

From Risk Assessment to Risk Management: Moving Beyond Checklists in 2025

Understand the evolution from risk assessment to strategic risk management in 2025. Learn why leading organizations are embedding risk into decision-making—and how GRC platforms like CERRIX support this shift.

What is risk management? A strategic guide for leaders in 2025

How Audit Firms Embed ISQM into Daily Practice

In our second ISQM webinar, experts from RSM, Grant Thornton, and CERRIX shared practical insights on how audit firms can embed ISQM into the heart of their operations.

Embedding ISQM 1 into the DNA of Your Audit Firm: A Risk-Based Approach to Quality Management

Discover how to implement ISQM 1 with a risk-based approach. Learn how audit firms can embed quality management into daily operations and governance.

CERRIX User Conference 2025

Op 12 maart 2025 kwamen marktleiders, verzekeringsexperts en CERRIX-klanten samen voor de CERRIX User Conference 2025, een dag van kennisuitwisseling, inzichtelijke discussies en samenwerking over de toekomst van risicobeheer, compliance en AI-gestuurde GRC-oplossingen.

Van spreadsheets tot GRC-software: waarom pensioenfondsen een moderne benadering van risicobeheer nodig hebben

CERRIX en BR1GHT versterken langdurige samenwerking om oplossingen voor bestuur, risico, compliance en audit te verbeteren

DORA implementeren: van compliance tot veerkracht op lange termijn

Gebruik van GRC-software: uitdagingen overwinnen en succes behalen op het gebied van compliance