Video summary

Staff Presentation: Quality Control – Firm Risk Assessment Process

Main summary

Key takeaways

News and Commentary

Overview

This staff presentation explains how a firm must implement the risk assessment process component of QC 1000 (the PCAOB’s new quality control standard) as part of a firm’s overall QC system.

Background and timing

  • Adoption and approval
    • QC 1000’s standard and related amendments were adopted in May 2024.
    • The SEC approved the rules in September 2024.
  • Effective date: December 15, 2025
  • Design and implementation expectations
    • Firms must have their QC system (including the risk assessment process) designed and implemented by Dec. 15, 2025.
    • Firms must then operate the risk assessment process starting that date.
  • Incremental nature of requirements
    • The presenter notes firms have already begun implementation.
    • However, QC 1000’s risk assessment requirements are incremental, and work under other standards will not fully satisfy QC 1000 on its own.

Purpose of the risk assessment process in QC 1000

  • QC 1000 contains eight integrated components of a firm’s QC system.
  • Risk assessment is one of two process components (the other is monitoring and remediation).
  • The risk assessment process:
    • Identifies and assesses quality risks at least annually
    • Drives the design and implementation of quality responses
    • Works with monitoring/remediation to create a feedback loop for continuous improvement
  • A risk-based approach is intended to be:
    • Adaptable to changes in technology, regulation, and the business environment
    • Scalable as firms grow

What the process must include (core steps)

1. Establish quality objectives

  • QC 1000’s quality objectives are outcome-based and tied to six QC components.
  • QC 1000 sets a “floor rather than a ceiling”:
    • Firms generally may add objectives if needed
    • Firms cannot omit or weaken mandatory objectives
  • The presentation frames the overarching QC system objective as providing reasonable assurance that:
    • Personnel and participants comply with professional/legal requirements and responsibilities, and
    • Engagement reports comply with applicable requirements
  • Firms may create subobjectives to connect responsibilities (e.g., hiring, development, retention) to risks and accountability.

2. Identify and assess “quality risks”

  • A quality risk is a risk (including from non-intentional circumstances) that has a reasonable possibility of occurring and, if it occurs, could adversely affect the achievement of a quality objective.
  • Firms must first understand conditions/events/activities that could harm quality objectives, including:
    • The firm’s nature and circumstances
    • The nature and circumstances of engagements
    • Other relevant information
  • Risk identification must be specific to the firm and its engagements, not generic.
  • The presentation emphasizes considering combinations of risks, not only individual risks in isolation.

3. Design and implement quality responses

  • Quality responses are policies and procedures designed to address quality risks and reduce the risk of failing to achieve quality objectives.
  • Some responses are specified/mandatory in QC 1000 (with additional mandatory requirements for larger firms in certain cases).
  • Responses must be based on assessed risks and tailored in nature, timing, and extent:
    • More significant or frequently recurring risks warrant more extensive responses
  • Responses may be implemented at the:
    • Firm level
    • Engagement level
    • Or both

Example used to illustrate the approach

The presenter walks through an example involving highly distributed management authority (no clear national office/HQ).

  • Steps shown:
    1. Identify a condition (unclear lines of responsibility/escalation).
    2. Determine it meets the “reasonable possibility” threshold for adversely affecting a specific quality objective—here, timely communication of ethics/independence violations to the operational responsibility person.
    3. Assess it as a quality risk and design responses beyond generic specified responses, such as:
      • Ethics/independence-specific escalation and communication protocols (e.g., severity ratings, mailbox/hotline)
      • Clearer lines of responsibility

Ongoing/iterative nature of risk assessment

  • Risk assessment is iterative and ongoing, not strictly linear from annual reviews.
  • Between annual assessments, firms must proactively address new or emerging risks by updating:
    • Quality objectives
    • Quality risks
    • Quality responses (as needed)
  • Firms must establish policies/procedures to monitor for changes from internal and external sources, including:
    • Mergers/acquisitions
    • New industries/engagements
    • Changes in regulatory requirements
    • Changes in firm structure (e.g., joining a network)
    • External factors affecting engagement risk (example: interest rate sensitivity for valuation risks)

QC 1000 timeline example for larger firms

  • An illustrative requirement: for larger firms, QC 1000 may require by the effective date (Dec. 15, 2025) the automation of identifying independence-impairing security holdings.
  • The key takeaway: firms must have relevant processes ready to operate by the effective date.

Resources and contact

  • The presenter directs viewers to the PCAOB’s QC implementation web page, including staff presentations and guidance materials.
  • The presenter notes there is a form/phone number for standards-related inquiries.
  • The presenter also references consulting the PCAOB’s adopting release and related implementation resources.

Presenters / contributors

  • David Ellum — Assistant, PCAOB Office of the Chief Auditor (presenter)

Original video