A firm risk assessment under SQMS No. 1 requires three connected pieces (paragraphs 24-27):
After working with several firms through the implementation, here’s my take on the guidance and some formatting and template tips if you’re planning to design your own matrix. If you’re using the AICPA matrix – see my article on that here.
SQMS No. 1 prescribes quality objectives for each component in paragraphs 29–34. Paragraph A44 specifcially states “that it is unlikely that the firm would find it necessary to establish additional quality objectives.”
For most firms, this first step is fairly straightforward. Take the objectives straight from the standard, and determine whether each is relevant to your firm's circumstances.
I’ve developed a Risk Matrix that is excel based and starts with the objectives prescribed under SQMS No. 1. Each objective has a dropdown to select whether the objective is relevant and space to document if it is not relevant (I pre-document common scenarios for firms to tailor).
Each objective is then pre-linked to the suggested quality risks associated with it.
Once the objectives are established, the firm is required to identify and assess the risks that could prevent those objectives from being achieved. Those risks include conditions, events, circumstances, actions, or inactions that could adversely affect achievement of the quality objectives (paragraph 26).
Those considerations include things like:
The standard does not expect firms to identify every imaginable risk – but you do have to identify “quality risks”. A quality risk is one that has a reasonable possibility of occurring and, individually or together with other risks, adversely affecting achievement of one or more quality objectives.
The challenge is that the available libraries contain a lot of risks, and many are repetitive or address substantially the same issue using different language.
The goal is not to copy every sample risk into your risk assessment, but rather to determine which risks actually have a reasonable possibility of affecting achievement of your firm's objectives.
For most firms, I recommend getting the appropriate leadership together and working through the risks in a meeting.
This is where the risk assessment becomes useful instead of becoming a documentation exercise.
Discuss questions like:
Those conversations help determine whether the sample risks actually fit the firm and whether additional firm-specific risks need to be added.
Within my Risk Matrix the objectives tab is followed by a Risk Assessment tab. As I built the matrix for individual firms, I reviewed just about every risk resource there is, wrote risks, and tailored the matrix. Firms who purchase the Matrix or Toolkit now just tailor the documentation to their actual firm risks.
The matrix has three versions:
Each includes pre-drafted, general risk language commonly applicable to that type of firm. The firm still evaluates and tailors every risk to its own circumstances.
Each risk also includes separate Likelihood and Magnitude ratings of Low, Medium, or High with general documentation the firm can tailor to align with its actual risk profile.
Another important formatting tip included in the matrix - each risk links back to the applicable quality objective and forward to the response designed to address it.
That connection is the whole point of the risk assessment.
Once the firm identifies a quality risk, it has to determine which policies and procedures will address the risk (paragraph 27). Just like a risk assessment for your clients, identifying the risk is only half the exercise. The firm then needs to determine what response, or combination of responses, will address it.
Importantly, SQMS No. 1 specifically says:
“The firm should design and implement responses to address the quality risks in a manner that is based on, and responsive to, the reasons for the assessments given to the quality risks.”
Many of your firm's procedures already exist and are occurring. The question is, are they documented accurately in line with your true risks?
Regardless of where the starting language comes from, the firm still needs a risk assessment supporting the policies and procedures it ultimately adopts.
This is the practical shift SQMS No. 1 is trying to create: start with the risk, not the policy manual. This is an important shift.
If a policy or procedure does not tie back to an identified risk, stop and ask why it’s there:
That is the value of a risk-based quality management system.
SQMS No. 1 reinforces this connection by requiring the firm's documentation to describe its responses and how those responses address the identified quality risks (paragraph 59).
Once policies and procedures are finalized, they cannot simply live inside a risk assessment workbook that no one else sees.
SQMS No. 1 requires relevant information to be communicated to personnel and engagement teams in a way that allows them to understand and carry out their responsibilities (paragraph 34). The firm's documentation also has to support a consistent understanding of the system of quality management, including personnel's roles and responsibilities (paragraph 58).
The standard does not prescribe a particular format for that communication. Practically, though, your final policies and procedures need to be organized in a way that can actually be communicated to the people expected to follow them.
Policies and procedures are maintained on the final tab of the matrix and formatted so they can be easily exported for communication to firm personnel.
I’ve included general policies and procedures that seem to be relevant to most firms in the firm-type the matrix applies to. Those responses are pre-linked directly back to the risk (or risks) they are designed to address.
That closes the loop:
If a policy does not tie to a risk, it should prompt another look:
That evaluation is one of the most valuable parts of the process.
The risk assessment may end with policies and procedures, but the system of quality management does not.
SQMS No. 1 requires firms to establish a monitoring and remediation process that provides information about the design, implementation, and operation of the system (paragraph 36). When designing monitoring activities, firms are specifically required to consider the reasons for their risk assessments and the design of their responses (paragraph 38).
As you finalize each policy or procedure, it is worth asking:
You do not have to build the entire monitoring program while performing the risk assessment. If you create policies today without thinking about how the firm could ever demonstrate or monitor them, you may create a much bigger project for yourself later.
Each policy and procedure includes fields suggesting where related monitoring occurs and what evidence may support that monitoring.
In the full SQMS Toolkit, those references connect to monitoring templates and checklists designed for the related policies and procedures.
That extends the documentation one step further:
A reviewer (partner or peer reviewer) should be able to follow the logic from beginning to end:
The format can look different from firm to firm.
SQMS No. 1 specifically recognizes that a less complex firm may document its objectives, risks, and responses in a single document, while a more complex firm may need a more formal risk assessment process (paragraph A40).
What matters is that the documentation clearly connects the pieces.
If you are still working through the AICPA Example Risk Assessment Template and trying to determine what to do with the response references and Practice Aid, start here:
That article walks through the mechanics of moving from the AICPA template into firm-specific documentation.
This article addresses the next question: what should the resulting risk assessment actually show?
A risk assessment does not need to be complicated.
The finished documentation should make the relationship easy to follow:
And as monitoring becomes the focus, that relationship should continue:
That is what turns a list of policies into a risk-based system of quality management.
Learn more about SQMS No. 1 SupportThis article is intended for general educational purposes and reflects practical experience applying SQMS No. 1. It is not authoritative AICPA guidance or a substitute for reviewing the applicable professional standards and considering your firm's specific facts and circumstances.
Email me if you're deciding how to approach your firm's documentation, or want to see the Risk Assessment Matrix and the rest of the SQMS Toolkit.