← Resources

What Are You Actually Supposed to Document in an SQMS Risk Assessment?

August 25, 2026

A firm risk assessment under SQMS No. 1 requires three connected pieces (paragraphs 24-27):

Quality Objectives
Quality Risks
Responses
Documentation requirementYour firm's documentation should include its quality objectives and quality risks, along with a description of the responses and how those responses address the identified risks (paragraph 59).

After working with several firms through the implementation, here’s my take on the guidance and some formatting and template tips if you’re planning to design your own matrix. If you’re using the AICPA matrix – see my article on that here.

1

Quality Objectives

SQMS No. 1 prescribes quality objectives for each component in paragraphs 29–34. Paragraph A44 specifcially states “that it is unlikely that the firm would find it necessary to establish additional quality objectives.”

For most firms, this first step is fairly straightforward. Take the objectives straight from the standard, and determine whether each is relevant to your firm's circumstances.

If something is not relevant, document why and move on.
How are Objectives documented in the CCC Risk Matrix?

I’ve developed a Risk Matrix that is excel based and starts with the objectives prescribed under SQMS No. 1. Each objective has a dropdown to select whether the objective is relevant and space to document if it is not relevant (I pre-document common scenarios for firms to tailor).

Each objective is then pre-linked to the suggested quality risks associated with it.

Linking risks to objectives gives the firm, leadership and the peer reviewer a clean way to see that every applicable quality objective has been considered in the risk assessment.
Objective
Applicable Risks
2

Quality Risks

Once the objectives are established, the firm is required to identify and assess the risks that could prevent those objectives from being achieved. Those risks include conditions, events, circumstances, actions, or inactions that could adversely affect achievement of the quality objectives (paragraph 26).

Those considerations include things like:

  • firm size and complexity;
  • operating structure;
  • leadership;
  • staffing and other resources;
  • strategic and operational decisions;
  • technology and service providers;
  • the types of engagements performed; and
  • the types of entities served.

The standard does not expect firms to identify every imaginable risk – but you do have to identify “quality risks”. A quality risk is one that has a reasonable possibility of occurring and, individually or together with other risks, adversely affecting achievement of one or more quality objectives.

You do not have to write every risk from scratch.

  • The AICPA Quality Management Practice Aid includes dozens of pages of potential quality risks that firms can use as a starting point.
  • If your firm uses PPC, they also have materials with example risks.
  • You can also identify and draft risks based on your own assessment of the firm.

The challenge is that the available libraries contain a lot of risks, and many are repetitive or address substantially the same issue using different language.

The goal is not to copy every sample risk into your risk assessment, but rather to determine which risks actually have a reasonable possibility of affecting achievement of your firm's objectives.

I recommend discussing risks live.

For most firms, I recommend getting the appropriate leadership together and working through the risks in a meeting.

This is where the risk assessment becomes useful instead of becoming a documentation exercise.

Discuss questions like:

  • Where is the firm most vulnerable?
  • Where is the firm heavily dependent on one person?
  • Where have issues occurred before?
  • Are there engagement types that require specialized knowledge?
  • Are staffing or capacity constraints creating risk?
  • Are there significant technology dependencies?
  • Has the firm grown, merged, added offices, or changed its service mix?
  • Are there processes that work primarily because one person knows how to do them?

Those conversations help determine whether the sample risks actually fit the firm and whether additional firm-specific risks need to be added.

No.
Do risks have to be scored?
SQMS No. 1 does not require formal ratings or scores. The application guidance specifically says firms may use them, but they are not required (paragraph A50).
How does CC document risks in the Risk Assessment Matrix?

Within my Risk Matrix the objectives tab is followed by a Risk Assessment tab. As I built the matrix for individual firms, I reviewed just about every risk resource there is, wrote risks, and tailored the matrix. Firms who purchase the Matrix or Toolkit now just tailor the documentation to their actual firm risks.

The matrix has three versions:

  • Sole Practitioner
  • Single-Office Firm
  • Multi-Office Firm with Centralized Leadership

Each includes pre-drafted, general risk language commonly applicable to that type of firm. The firm still evaluates and tailors every risk to its own circumstances.

Each risk also includes separate Likelihood and Magnitude ratings of Low, Medium, or High with general documentation the firm can tailor to align with its actual risk profile.

Another important formatting tip included in the matrix - each risk links back to the applicable quality objective and forward to the response designed to address it.

This makes it crystal clear you’ve evaluated each objective, and responded to every risk.
Objective
Risk
Response

That connection is the whole point of the risk assessment.

3

Responses

Once the firm identifies a quality risk, it has to determine which policies and procedures will address the risk (paragraph 27). Just like a risk assessment for your clients, identifying the risk is only half the exercise. The firm then needs to determine what response, or combination of responses, will address it.

Importantly, SQMS No. 1 specifically says:

“The firm should design and implement responses to address the quality risks in a manner that is based on, and responsive to, the reasons for the assessments given to the quality risks.”
Key takeawayAt the end of the day, the final result of this portion of your risk assessment is your firm's quality management policies and procedures.

Many of your firm's procedures already exist and are occurring. The question is, are they documented accurately in line with your true risks?

  • You may need to draft some responses from scratch.
  • Some firms use suggested policies and procedures from the AICPA Practice Aid.
  • Many firms use PPC's quality management policies and procedures.

Regardless of where the starting language comes from, the firm still needs a risk assessment supporting the policies and procedures it ultimately adopts.

This is the practical shift SQMS No. 1 is trying to create: start with the risk, not the policy manual. This is an important shift.

The question is not
Which quality management policies should the firm adopt?
The better question is
What risk has the firm identified, and what policy or procedure is necessary to address it?

If a policy or procedure does not tie back to an identified risk, stop and ask why it’s there:

  • It may be required elsewhere in the standard.
  • It may indicate that the firm missed a risk during its assessment.
  • Or it may simply be legacy or sample language that is not relevant to the firm.

That is the value of a risk-based quality management system.

The goal is not
To have the longest policy manual.
The goal is
To have policies and procedures that address the risks the firm actually faces.

SQMS No. 1 reinforces this connection by requiring the firm's documentation to describe its responses and how those responses address the identified quality risks (paragraph 59).

Your final policies also need to be usable.

Once policies and procedures are finalized, they cannot simply live inside a risk assessment workbook that no one else sees.

SQMS No. 1 requires relevant information to be communicated to personnel and engagement teams in a way that allows them to understand and carry out their responsibilities (paragraph 34). The firm's documentation also has to support a consistent understanding of the system of quality management, including personnel's roles and responsibilities (paragraph 58).

The standard does not prescribe a particular format for that communication. Practically, though, your final policies and procedures need to be organized in a way that can actually be communicated to the people expected to follow them.

How does CC document responses (policies/procedures) in the Risk Assessment Matrix?

Policies and procedures are maintained on the final tab of the matrix and formatted so they can be easily exported for communication to firm personnel.

I’ve included general policies and procedures that seem to be relevant to most firms in the firm-type the matrix applies to. Those responses are pre-linked directly back to the risk (or risks) they are designed to address.

That closes the loop:

Objective
Risk
Policy or Procedure

If a policy does not tie to a risk, it should prompt another look:

  • Is the policy actually necessary?
  • Is there an unidentified risk?
  • Or is the firm carrying forward language simply because it appeared in a sample manual?

That evaluation is one of the most valuable parts of the process.

One more thing: keep monitoring in mind.

The risk assessment may end with policies and procedures, but the system of quality management does not.

SQMS No. 1 requires firms to establish a monitoring and remediation process that provides information about the design, implementation, and operation of the system (paragraph 36). When designing monitoring activities, firms are specifically required to consider the reasons for their risk assessments and the design of their responses (paragraph 38).

As you finalize each policy or procedure, it is worth asking:

  • What evidence will exist if this procedure is actually performed?
  • Who will be responsible?
  • Where will that evidence live?
  • How could the firm determine whether the response is operating as intended?

You do not have to build the entire monitoring program while performing the risk assessment. If you create policies today without thinking about how the firm could ever demonstrate or monitor them, you may create a much bigger project for yourself later.

DeadlineMonitoring needs to be operating in time to provide the information necessary for the firm's first annual evaluation, which must be completed no later than December 15, 2026.
How does CC consider monitoring in the Risk Assessment Matrix?

Each policy and procedure includes fields suggesting where related monitoring occurs and what evidence may support that monitoring.

In the full SQMS Toolkit, those references connect to monitoring templates and checklists designed for the related policies and procedures.

That extends the documentation one step further:

Objective
Risk
Response
Evidence and Monitoring

What should the finished risk assessment show?

A reviewer (partner or peer reviewer) should be able to follow the logic from beginning to end:

Quality Objective
What is the firm required to achieve?
Quality Risk
What could prevent the firm from achieving it?
Risk Assessment
How relevant and significant is that risk to this firm?
Response
What policy or procedure addresses it?
Evidence and Monitoring
How will the firm know it's operating?

The format can look different from firm to firm.

SQMS No. 1 specifically recognizes that a less complex firm may document its objectives, risks, and responses in a single document, while a more complex firm may need a more formal risk assessment process (paragraph A40).

What matters is that the documentation clearly connects the pieces.

Using the AICPA Risk Assessment Template?

If you are still working through the AICPA Example Risk Assessment Template and trying to determine what to do with the response references and Practice Aid, start here:

That article walks through the mechanics of moving from the AICPA template into firm-specific documentation.

This article addresses the next question: what should the resulting risk assessment actually show?

Final thoughts

A risk assessment does not need to be complicated.

  • Start with the objectives prescribed by SQMS No. 1.
  • Determine the risks that actually apply to your firm.
  • Assess those risks.
  • Then make sure every policy and procedure the firm adopts has a reason for being there.

The finished documentation should make the relationship easy to follow:

Objective
Risk
Response

And as monitoring becomes the focus, that relationship should continue:

Objective
Risk
Response
Evidence and Monitoring

That is what turns a list of policies into a risk-based system of quality management.

Learn more about SQMS No. 1 Support

This article is intended for general educational purposes and reflects practical experience applying SQMS No. 1. It is not authoritative AICPA guidance or a substitute for reviewing the applicable professional standards and considering your firm's specific facts and circumstances.

Next step

Talk through your firm's risk assessment.

Email me if you're deciding how to approach your firm's documentation, or want to see the Risk Assessment Matrix and the rest of the SQMS Toolkit.