Video summary
Staff Presentation: Quality Control – Firm Risk Assessment Process
Main summary
Key takeaways
Overview
This staff presentation explains how a firm must implement the risk assessment process component of QC 1000 (the PCAOB’s new quality control standard) as part of a firm’s overall QC system.
Background and timing
- Adoption and approval
- QC 1000’s standard and related amendments were adopted in May 2024.
- The SEC approved the rules in September 2024.
- Effective date: December 15, 2025
- Design and implementation expectations
- Firms must have their QC system (including the risk assessment process) designed and implemented by Dec. 15, 2025.
- Firms must then operate the risk assessment process starting that date.
- Incremental nature of requirements
- The presenter notes firms have already begun implementation.
- However, QC 1000’s risk assessment requirements are incremental, and work under other standards will not fully satisfy QC 1000 on its own.
Purpose of the risk assessment process in QC 1000
- QC 1000 contains eight integrated components of a firm’s QC system.
- Risk assessment is one of two process components (the other is monitoring and remediation).
- The risk assessment process:
- Identifies and assesses quality risks at least annually
- Drives the design and implementation of quality responses
- Works with monitoring/remediation to create a feedback loop for continuous improvement
- A risk-based approach is intended to be:
- Adaptable to changes in technology, regulation, and the business environment
- Scalable as firms grow
What the process must include (core steps)
1. Establish quality objectives
- QC 1000’s quality objectives are outcome-based and tied to six QC components.
- QC 1000 sets a “floor rather than a ceiling”:
- Firms generally may add objectives if needed
- Firms cannot omit or weaken mandatory objectives
- The presentation frames the overarching QC system objective as providing reasonable assurance that:
- Personnel and participants comply with professional/legal requirements and responsibilities, and
- Engagement reports comply with applicable requirements
- Firms may create subobjectives to connect responsibilities (e.g., hiring, development, retention) to risks and accountability.
2. Identify and assess “quality risks”
- A quality risk is a risk (including from non-intentional circumstances) that has a reasonable possibility of occurring and, if it occurs, could adversely affect the achievement of a quality objective.
- Firms must first understand conditions/events/activities that could harm quality objectives, including:
- The firm’s nature and circumstances
- The nature and circumstances of engagements
- Other relevant information
- Risk identification must be specific to the firm and its engagements, not generic.
- The presentation emphasizes considering combinations of risks, not only individual risks in isolation.
3. Design and implement quality responses
- Quality responses are policies and procedures designed to address quality risks and reduce the risk of failing to achieve quality objectives.
- Some responses are specified/mandatory in QC 1000 (with additional mandatory requirements for larger firms in certain cases).
- Responses must be based on assessed risks and tailored in nature, timing, and extent:
- More significant or frequently recurring risks warrant more extensive responses
- Responses may be implemented at the:
- Firm level
- Engagement level
- Or both
Example used to illustrate the approach
The presenter walks through an example involving highly distributed management authority (no clear national office/HQ).
- Steps shown:
- Identify a condition (unclear lines of responsibility/escalation).
- Determine it meets the “reasonable possibility” threshold for adversely affecting a specific quality objective—here, timely communication of ethics/independence violations to the operational responsibility person.
- Assess it as a quality risk and design responses beyond generic specified responses, such as:
- Ethics/independence-specific escalation and communication protocols (e.g., severity ratings, mailbox/hotline)
- Clearer lines of responsibility
Ongoing/iterative nature of risk assessment
- Risk assessment is iterative and ongoing, not strictly linear from annual reviews.
- Between annual assessments, firms must proactively address new or emerging risks by updating:
- Quality objectives
- Quality risks
- Quality responses (as needed)
- Firms must establish policies/procedures to monitor for changes from internal and external sources, including:
- Mergers/acquisitions
- New industries/engagements
- Changes in regulatory requirements
- Changes in firm structure (e.g., joining a network)
- External factors affecting engagement risk (example: interest rate sensitivity for valuation risks)
QC 1000 timeline example for larger firms
- An illustrative requirement: for larger firms, QC 1000 may require by the effective date (Dec. 15, 2025) the automation of identifying independence-impairing security holdings.
- The key takeaway: firms must have relevant processes ready to operate by the effective date.
Resources and contact
- The presenter directs viewers to the PCAOB’s QC implementation web page, including staff presentations and guidance materials.
- The presenter notes there is a form/phone number for standards-related inquiries.
- The presenter also references consulting the PCAOB’s adopting release and related implementation resources.
Presenters / contributors
- David Ellum — Assistant, PCAOB Office of the Chief Auditor (presenter)