8.4 Quality Assurance & Peer Review
Key Takeaways
Engagement supervision, engagement-level review and organisation-wide quality assurance are related but distinct controls.
A reviewer must have sufficient competence, authority, time and objectivity for the work being evaluated.
Quality review focuses on significant judgments, evidence, conclusions and compliance; it does not transfer responsibility from the engagement team.
Internal assessments and independent external or peer reviews identify systemic strengths and deficiencies and require tracked remedial action.
Quality indicators should combine timeliness with evidence quality, recurring findings, stakeholder usefulness and completion of corrective action.
8.4 Quality Assurance & Peer Review
Annex II expressly includes participation in quality assurance and peer review. These activities provide confidence that audit work is performed under applicable standards and the organisation's methodology, and they identify systemic improvements. They do not guarantee that every judgment is correct or eliminate the engagement team's responsibility.
Layers of quality control
Distinguish several layers:
- Direction and supervision occur throughout the engagement and help the team perform the work correctly.
- Engagement review checks work, evidence and conclusions before reporting.
- Engagement quality review, where required by the applicable framework or organisational criteria, provides an objective evaluation of significant judgments by an eligible reviewer outside the engagement team.
- Internal quality assessments or inspections examine a sample of completed work and the operation of the audit system.
- External assessment or peer review brings independent evaluation from outside the function or organisation under the relevant framework.
The precise terminology and mandatory scope differ among financial, internal and public-sector audit frameworks. Do not assume that every engagement requires the same separate quality reviewer. Apply the standard, law and organisational criteria governing the work.
Reviewer competence and objectivity
Choose reviewers with appropriate technical experience, knowledge of the audit context, authority to challenge and enough time. Objectivity can be threatened if the reviewer made the judgments now under review, has operational responsibility for the subject, or faces incentives to approve quickly.
Safeguards can include different reporting lines, cooling-off arrangements defined by policy, consultation with another specialist or reassignment. The safeguard must address the actual threat; arbitrary universal rotation periods should not be invented.
What engagement quality review examines
Focus on significant matters: independence, risk assessment, materiality, scope changes, difficult consultations, contradictory evidence, sampling or estimates, proposed findings, responses from the audited entity and the relationship between evidence and the report. Review whether the conclusion is proportionate and whether unresolved differences remain.
The reviewer should not reperform the entire audit or become a hidden co-author. The engagement leader retains responsibility. Complete required review before the report date, document matters reviewed and resolve significant concerns under the applicable process.
Internal assessment and inspection
An internal quality programme combines ongoing monitoring with periodic assessment. Select files using risk as well as rotation—for example, new methods, high public interest, complex technology, prior deficiencies or new leaders. Use criteria derived from the applicable standards and approved methodology.
Classify findings by significance and cause. A missing signature may indicate a documentation lapse; repeated unsupported conclusions may indicate training, supervision, workload or methodological failure. Look across files for patterns rather than treating each symptom in isolation.
The inspected team should have a factual-response opportunity. Quality staff then agree or assign actions, owners and deadlines, and verify implementation. Quality functions lose credibility if they issue recommendations but do not follow them.
External and peer review
Peer review can evaluate institutional arrangements, independence, strategy, methodology, engagement performance or selected themes. Define scope, criteria, access, confidentiality, conflicts, reporting and follow-up in advance. Reviewers need access to enough evidence while respecting legal restrictions and personal or sensitive data.
Independence is more important than organisational familiarity. A reciprocal review arrangement can create self-interest or familiarity threats if the same organisations repeatedly review one another without safeguards.
Reporting and improvement
Report strengths as well as deficiencies, but do not dilute significant issues with average scores. Useful measures include recurring inspection findings, time to resolve review notes, report corrections, consultation use, stakeholder usefulness, overdue quality actions and whether root causes were addressed.
Share anonymised lessons through methodology updates and training. Preserve confidentiality and avoid using quality findings merely to punish individuals; distinguish individual conduct from system design. Where a deficiency could undermine an issued report, follow the governing framework for consultation, correction or notification.
Quality reporting should also disclose the scope and limits of the assessment: which engagements, periods and criteria were examined, how files were selected, and whether any access restriction affected the conclusion. A clean result over a small low-risk sample is not evidence about the entire audit portfolio unless the design supports that inference.
Mini-case
An inspection finds that three performance audits used strong evidence but recommendations lacked responsible actors or measurable intended results. The systemic response should examine report guidance, review checklists and training, not merely ask each team to add a sentence to closed files. An owner, deadline, pilot revision and follow-up test convert the observation into quality improvement.
Which statement correctly distinguishes engagement review from quality assurance?
Engagement review checks current work, while broader quality assessment also evaluates how the audit system operates across work
They are identical terms in every framework
Quality assurance removes the engagement leader’s responsibility
Only external reviewers may examine evidence
What is essential for a quality reviewer?
Participation in every original judgment
Relevant competence, authority, time and objectivity
A promise never to challenge the team
Operational responsibility for the audited process
What should an inspection do after identifying repeated unsupported conclusions?
Treat each as an isolated missing signature
Publish confidential working papers
Assess root causes and assign tracked corrective action
Automatically withdraw every report
Which claim about a separate engagement quality review is safest?
It is mandatory for every audit of any type
It replaces normal supervision
It may be completed after the report whenever convenient
Its requirement and scope depend on the governing framework and organisational criteria
Sections you finish are checked off in the contents.