Quality Management Services


Audit Quality Advisory Services for Accounting Firms

Quality Management Services

Quality management is a critical component for firms of all audit practices, including issuer and broker-dealer audits. Firms are required to comply with quality management and quality control standards related to their system of quality management. Specifically, the IAASB, AICPA, and PCAOB have adopted ISQM 1, SQMS 1, and QC 1000, respectively. As a result, firms that are required to follow IAASB, AICPA or PCAOB standards need to reconsider their quality management systems and implement policies and procedures to comply with these requirements.


The following diagrams depicts the steps that a firm should undertake to initially adopt and implement the quality management standards and the iterative and cyclical nature of operating their system of quality management on an annual basis:

Through our experiences evaluating systems of quality control at firms that operate domestically and internationally and completing hundreds of firm inspections, we as Advisors, meet firms where they are and understand the significant effort and the changes required by firms to implement and operate their system of quality management under the new quality management framework. These required changes will affect firms around the globe due to the amount of effort involved given the rigor of these standards. 


We have supported firms' initiatives to establish the appropriate policies, processes and systems to address the changes required in the adoption of the quality management standards. These changes include developing a robust risk assessment process, establishing governance and leadership controls, expanding firm policies and controls around independence and ethics requirements, and identifying and establishing appropriate policies and controls for firm technological, intellectual, and human resources. This work also includes developing or improving processes and controls over monitoring and remediation, including root cause analyses.


JGA has the experience and the team to help firms implement and operate their system of quality management and comply with the quality management standards.

Our Services Include:

Risk Assessment


  • Identify the “what could go wrongs” 
  • Perform a risk evaluation 
  • Assist or perform risk heat mapping development and implementation 
  • Refine and update risks 

Implementation and Training


  • Assist with new or revised control implementation 
  • Support reorganization/realignment 
  • Develop, deliver, and consult on training programs 

Monitoring


  • At firm level 
  • Develop and implement score cards and QC KPIs 
  • At engagement level 
  • Perform pre- and post-inspections 
  • Perform root cause analysis, including
  • interviews with engagement teams 

Evaluation and Testing


  • Assist with the annual evaluation of the system of Quality Management including development, implementation and evaluation 

Quality Management Readiness 


  • Perform an initial risk assessment 
  • Perform a gap health check on key components of the firm’s QC process 
  • Support QC documentation efforts 
  • Advise on software implementation 
  • Refine and assist with developing QC processes 

Root Cause and Remediation 


  • Root Cause 
  • Assist with methodology / audit tool development 
  • Conduct interviews 
  • Perform and analysis of root cause findings 
  • Complete and report on root cause analysis 
  • Remediation 
  • Design and execute on remedial action plans for firm-level deficiencies 
  • Assist with engagement level remediation and resolution
March 30, 2026
In a previous article, Back to Basics: Audit Documentation Failures Have Become Dangerous Low Hanging Fruit , we highlighted how audit documentation had quietly re-emerged as a source of regulatory risk after years of relative deprioritization. While PCAOB Auditing Standard 1215, Audit Documentation (AS 1215), has historically been cited less frequently than other standards, our direct experience from recent inspection activity, enforcement actions, and internal inspection results, demonstrate that documentation failures are increasingly treated as indicators of deeper execution, supervision, and quality management breakdowns. In today’s environment, audit documentation is no longer merely a record of work performed. It is the primary evidence inspectors rely on to evaluate whether an engagement was properly planned, executed, and supported at the time the auditor’s report was issued. What has been low-hanging fruit now requires firms to close these gaps and transform them into a load-bearing foundation for audit quality. From Rare Enforcement to Systemic Inspection Risk AS 1215 establishes clear requirements regarding what must be documented, when documentation must be completed, and how engagement files must be assembled and retained. As discussed in our prior article, failures to comply with these requirements were historically viewed as technical or secondary issues, often resulting in inspection comments rather than enforcement action. That distinction is no longer meaningful. Recent enforcement actions involving backdating, improper (both intentionally, and inadvertent) modification of workpapers, and failure to timely assemble a complete audit file reflect an evolving regulatory view. Documentation failures do not simply violate procedural requirements; they call into question the credibility of the audit opinion itself. More importantly, beyond enforcement, documentation deficiencies are increasingly cited as core inspection findings. Inspectors are challenging situations where engagement teams assert that work was performed but cannot demonstrate that work within the archived file. In these cases, the absence of timely, complete, and clear documentation is no longer treated as a formality. It is treated as evidence that the engagement may not have been properly executed, supervised, or supported in accordance with PCAOB standards. This represents a fundamental shift. Documentation is no longer “low-hanging fruit.” It is a systemic inspection risk that cuts across execution, supervision, and firm-level quality management. From Misconduct to Execution Failures Pervasive documentation failures that do not involve intentional misconduct but still result in non-compliance are increasingly observed. For example, reviewer signoffs occurring near the documentation completion date, rather than contemporaneously with the performance of audit procedures, raise questions about whether effective supervision occurred during the audit or was deferred to meeting archiving deadlines. Similarly, engagement teams may assert that key judgments can be explained verbally, even when those judgments are not clearly documented in the audit file. In today’s environment, the distinction between “we can explain it” and “it is clearly documented” is critical. If procedures, judgments, and conclusions are not evident in the documentation itself, inspectors increasingly conclude that the work was not performed in accordance with PCAOB standards. The issue is not whether the engagement team can explain what they did after the fact. The issue is whether the archived documentation allows an experienced auditor, with no prior connection to the engagement, to understand the procedures performed, evidence obtained, and conclusions reached at the time of the auditor’s report. When documentation fails to reach that standard, inspectors are increasingly concluding that the audit itself was not properly executed, regardless of intent. This reflects an important shift. Documentation failures are no longer viewed primarily as misconduct. They are viewed as symptoms of execution breakdowns, including delayed supervision, compressed review cycles, and audit workflows that defer documentation until the end of the engagement. As a result, AS 1215 has become a direct proxy for how audits are actually performed in practice. How the 14-Day Documentation Completion Requirement Changes the Risk Profile The execution risks are further amplified by the PCAOB’s shortened documentation completion timeline. Recent amendments to AS 1215 reduce the timeframe to assemble a complete and final audit file from 45 days to 14 days after the report release date. While this change may appear procedural, its implications are operational. Under this accelerated timeline, engagement teams no longer have a meaningful post-issuance window to resolve review notes, complete documentation, or finalize supervisory evidence. What were once viewed as “clean-up” activities are now more likely to result in timing violations and non-compliance. This shift places increased emphasis on: Contemporaneous documentation Real-time supervision Realistic workload and staffing models Audit Documentation as a Cornerstone of Audit Quality Audit documentation has long been described as low-hanging fruit in the inspection process. That characterization no longer reflects its role in today’s regulatory environment. Documentation now serves as the primary lens through which regulators assess whether an engagement was properly executed, supervised, and supported. With shortened timelines, expanded quality management expectations, and increased regulatory scrutiny, firms can no longer treat documentation as a downstream activity. It must be embedded into how engagements are planned, staffed, reviewed, and completed. In an environment where inspection conclusions are driven by what is, and what is not, in the audit file, strong documentation is not merely defensive. It is foundational to audit quality. At Johnson Global Advisory , we support firms in selecting, implementing, and optimizing these tools to meet their unique needs. For more insights, visit our blog or contact us to learn how we can help your firm AmplifyQuality®. For more information, please contact your JGA audit quality expert .
January 20, 2026
Introduction The accounting firm industry experienced a ground-breaking transaction in August of 2021 when TowerBrook acquired EisnerAmper, which marked the first private equity (“PE”) transaction of a large-scale accounting firm. This transaction was structured using an alternative practice structure (“APS”). Historically, licensing and independence rules have barred non-CPAs from owning accounting firms. Through an APS, a PE firm may invest in the non-attest entity with service lines such as tax advisory and consulting. The CPA partners retain control over the attest functions, which preserves regulatory compliance. While the APS model has been in existence since the 1990s, this August 2021 transaction brought new attention to this structure. What has followed is an extraordinary volume of deal activity. Per the CPA Trendlines (“CPAT”) Cornerstone report posted on November 18, 2025, CPAT has tracked over 115 PE-related transactions from 2020 to 2025, with over 80 transactions in 2025. While PE in the accounting firm space is no longer news, the pace and volume of transactions is certainly news-worthy. Impact of PE Investment The impact of PE investment on the accounting firm space is unprecedented. The APS has enabled PE to fuel billions of capital investment. PE-backed firms provide immediate payouts to partners at appealing valuations while providing access to capital to these firms for merger and acquisition growth, technology investments, and other priorities. Well-capitalized firms now have an improved ability to invest in technological capabilities, attract experienced talent to be more competitive for college graduates, and improve their market position. With new technologies, routine tasks are being automated such as data entry, tie-outs and controls testing, resulting in less time needed to perform certain audit procedures. What the regulators are saying At the AICPA December 2025 conference on Current SEC and PCAOB Developments, common topics were the presence of private equity in the accounting firm space and the opportunities and challenges that come with this investment. PCAOB Acting PCAOB Chair George Botic described that both transformative technologies (e.g., artificial intelligence or “AI”) and the continuing expansion of private equity investments in accounting firms are two developments that bring opportunities and challenges. Mr. Botic noted that while AI has enhanced risk assessment, reduced manual processes and made it possible to efficiently analyze entire populations of data (which can reduce the risk of missing irregularities or unusual patterns), that overreliance on AI may ultimately threaten auditors’ exercise of professional skepticism and judgment. As it relates to private equity, Mr. Botic noted that while these investments have the potential to enhance audit quality by increasing firm capacity and modernizing audit tools with advanced technologies, the presence of private equity presents a risk that firms shift incentives to prioritize profitability over audit quality. Mr. Botic stated, “Both AI and private equity investments in accounting firms carry the potential to truly reshape the profession. Yet these opportunities come with clear challenges to ensure that overreliance on AI and the pressures of private equity do not jeopardize audit quality.” SEC SEC Chair Atkins discussed in his remarks that he would like the PCAOB to modify its inspections process to place more reliance on the system of quality management and that inspection of certain engagements would inform the PCAOB if the firm’s system of quality management is effective. He also expressed a view that accountability for audit quality should move upward to firm leadership. How is a firm’s system of quality management (“SQM”) impacted? Today’s transforming environment has far-reaching impacts on a firm’s SQM. This publication will focus on risk assessment, governance and leadership, ethics and independence, resources, engagement performance, and monitoring and remediation. 
By Jackson Johnson September 30, 2025
With the effective date for SQMS 1 and QC 1000 fast approaching, firms of all sizes—especially small and sole practitioners—must take action to implement a system of quality management (SQM) that meets the new standards. The good news? You don’t have to start from scratch. Despite QC 1000’s implementation date deferral, the AICPA’s date hasn’t changed, and the international standards are already effective. It’s important to maintain momentum on the efforts toward implementation of all applicable standards for your firm. This article outlines 10 practical steps to help firms build their SQM. Each step includes actionable guidance and considerations for firms with limited resources, and ties into JGA’s broader thought leadership on quality management, risk assessment, and system evaluation. The 10 Steps to Build Your SQM Step 1: Establish a Project Team Form a team with the right mix of quality expertise and operational insight. For small firms, this may mean involving a manager who can grow into a leadership role or setting aside dedicated time as a sole practitioner. Recommended actions to consider: Identify internal champions with interest or experience in quality. Schedule recurring project meetings to maintain momentum. Join a peer group for support and shared learning. Step 2: Understanding and Awareness Document your firm’s business strategy, service offerings, and operational conditions. This step helps identify factors that may impact quality—such as remote work, new industries, or staff turnover. Recommended actions to consider: Conduct a strategy review with firm leadership. List recent changes in firm structure or engagement types. Use these insights to inform your risk assessment. Step 3: Assign Responsibilities Define who is accountable for the SQM. The new standards require clear delineation of ultimate and operational responsibility, including oversight of independence and monitoring. Recommended actions to consider: Assign roles based on existing responsibilities. Clarify delegation boundaries for managing partners. Document responsibilities in your quality manual. Step 4: Establish a Risk Assessment Function Design a process to identify and assess quality risks. This includes understanding conditions or events that could impact quality objectives. Recommended actions to consider: Create a risk assessment policy tailored to your firm. Use relatable examples to demystify risk factors. Leverage AICPA practice aids for structure and templates. Step 5: Perform the Initial Risk Assessment Conduct brainstorming sessions by component and document risks using the AICPA Risk Assessment Template. Include both formal and informal responses. Recommended actions to consider: Use the AICPA risk library to identify common risks. Tailor risks to your firm’s size and services. Include existing responses—even if informal—for evaluation. Step 6: Finalize the Gap Analysis Evaluate where your current responses fall short. This may include undocumented policies or areas where responses don’t fully address the risk. Recommended actions to consider: Identify gaps in governance, ethics, and technology. Determine which informal practices need formalization. Prioritize gaps based on risk severity and regulatory impact. Step 7: Implement Responses to Address the Gaps Develop policies and procedures to close gaps. Responses must be documented and operational. Recommended actions to consider: Draft policies that reflect your firm’s values and risks. Link procedures to specific quality objectives. Use existing documentation as a starting point. Step 8: Update Your Monitoring Process Move beyond peer review prep—monitoring should be continuous and system-wide. Recommended actions to consider: Assign monitoring responsibilities across the team. Incorporate testing of responses into internal inspections. Use dashboards or checklists to track progress. Step 9: Formalize Root Cause and Remediation Procedures Investigate deficiencies and document why they occurred. This step is essential for both system and engagement-level reviews. Recommended actions to consider: Conduct interviews to understand root causes. Use findings to improve policies and training. Apply remediation even if your firm only undergoes engagement reviews. Step 10: Initial Test of Design and Implementation Review documentation and walk through processes to ensure your system is operational and testable. Recommended actions to consider: Validate that each component is supported by evidence. Simulate a peer review to test your system. Confirm that objectives, risks, and responses align. Conclusion Implementing a system of quality management is not just a compliance exercise—it’s an opportunity to strengthen your firm’s foundation for audit quality, risk management, and long-term success. Whether you’re a sole practitioner or a small firm with a few partners, these 10 steps offer a scalable roadmap to meet the new standards. Ready to get started or need help refining your approach? Contact your JGA audit expert today to schedule a consultation and ensure your implementation is tailored to your firm’s needs. At Johnson Global Advisory , we support firms in selecting, implementing, and optimizing these tools to meet their unique needs. For more insights, visit our blog or contact us to learn how we can help your firm AmplifyQuality®.
Show More
September 10, 2026
In our previous alert, Open Board Meeting: PCAOB to Consider Adopting New Standards on General Responsibilities of the Auditor in Conducting an Audit, Quality Contro l, we discussed the PCAOB's plans to consider amendments to QC 1000 and related quality control reporting requirements. At its September 9, 2026 Open Meeting , the PCAOB adopted a series of amendments to QC 1000 and related reporting requirements designed to improve scalability, reduce implementation burden, and further align certain aspects of the standard with other quality management frameworks. While the amendments provide meaningful changes in several areas, firms remain responsible for establishing and maintaining an effective system of quality control starting December 15, 2026. The following table summarizes the key amendments adopted by the Board and JGA's insights regarding the implications for registered firms.
August 24, 2026
Introduction For many audit firms, obtaining registration with the Public Company Accounting Oversight Board (PCAOB) is viewed as a milestone that opens the door for firms to audit public companies (SEC registrants) and broker-dealers. While firms often focus heavily on completing the registration form, paying the registration fee, and obtaining PCAOB approval, many underestimate the significant ongoing responsibilities and risks that accompany registration.  The result is that some newly registered firms quickly discover that PCAOB registration is not simply a licensing exercise and gateway to additional audit revenue. Rather, it subjects the firm to a comprehensive oversight regime involving inspections, reporting requirements, quality control expectations, disciplinary authority and enforcement which results may be made public, and heightened scrutiny from regulators, investors, and audit committees. This article highlights several pitfalls that firms frequently fail to consider before becoming PCAOB registered. Registration Is Merely the Beginning, Not the End Many firms approach PCAOB registration as a compliance hurdle. In reality, registration represents the starting point of an ongoing regulatory relationship. Once registered, firms become subject to PCAOB inspection authority, reporting obligations, investigations, and disciplinary proceedings. Registered firms must take on recurring PCAOB filing requirements, including annual reporting and special reporting when specified events occur. Failure to comply can lead to sanctions, revocation proceedings, and reputational damage. Firms that register solely because a potential client requests the firm to do so often underestimate the resources required to maintain compliance year after year. PCAOB Inspections Can Be Far More Demanding Than Peer Review One of the most common misconceptions is that a firm with a successful AICPA peer review is well-positioned for PCAOB inspection. Although both peer reviews and PCAOB inspections evaluate audit quality, they are fundamentally different. PCAOB inspectors focus intensely on audit execution, documentation, professional skepticism, risk assessment, internal controls, and overall compliance with PCAOB standards and rules. Inspection findings can be severe even when a firm has received a clean peer review. Firms entering the public company audit space frequently discover that methodologies and documentation practices acceptable in the private-company environment may not withstand PCAOB inspection scrutiny. Thus, firms should be factoring into their decision-making that they will need to subscribe to modules within their current methodology that include PCAOB procedures to be performed for an audit and/or supplement their audit methodology with certain tools and templates. This would be specifically applicable for areas such as auditing estimates, testing internal controls over financial reporting, and evaluation of critical audit matters. JGA has seen situations where even though a firm has subscribed to a PCAOB-standards module in an auditing platform, the firm still had to supplement this with additional templates. Quality Control Systems Often Need Significant Enhancement Many firms register before fully assessing whether their quality control system can support PCAOB engagements. Areas commonly underestimated include: Engagement quality reviews – does the firm have sufficient EQR resources? Are the EQRs proficient in the requirements of AS 1220? Independence monitoring – does the firm have a well-established platform/repository to track its audit professionals’ investments and relationships as well as track and keep up to date the affiliate relationships of its audit clients? Consultation processes – are there appropriate experts within the firm that can be consulted on when questions arise related to SEC independence rules or PCAOB auditing standards? Or will the firm need to consult externally? Monitoring and remediation activities – does the firm have the appropriate experienced resources to maintain an effective monitoring program? Evaluation of technical competency of professionals working on PCAOB audits Training programs – will the firm have to call on external experts who are experienced in PCAOB standards to upskill its audit professionals in proper understanding of the requirements of the PCAOB auditing standards? Client acceptance procedures – does the firm have the appropriate access to affiliate and related party information to make informed client acceptance decisions? Audit methodology governance A firm may technically qualify for registration yet lack the infrastructure needed to execute PCAOB audits consistently. We have seen all-to-often this gap becoming visible during the firm's first PCAOB inspection with criticism of the firm’s technical competency cited as a pervasive deficiency in the first PCAOB inspection report. Independence Requirements Become More Complex Another overlooked challenge involves auditor independence. Firms accustomed to serving privately held businesses may not fully appreciate the complexity of SEC and PCAOB independence requirements. Relationships, services, and financial interests that may be permissible in other environments can create independence violations for issuer audits under SEC and PCAOB independence rules which would include: Providing bookkeeping assistance Valuation services Tax consulting arrangements Business relationships with audit clients Family and employment relationships Financial interests held by firm personnel Even inadvertent violations can have significant consequences, potentially requiring audits to be re-issued or resulting in regulatory scrutiny or enforcement repercussions. Public Company Audits Require Specialized Expertise Many firms assume experienced auditors can transition easily into issuer audits. Public company audits involve unique requirements related to areas such as: SEC reporting Internal control over financial reporting (ICFR) Critical audit matters (CAMs) Fraud considerations, including journal entry testing Related-party transactions PCAOB auditing standards such as testing estimates and audit committee communications Form AP reporting Without personnel who possess sufficient public company experience, firms may struggle to perform audits that meet PCAOB expectations. Our experience has been that firms need to invest in education and training programs/curriculum for its audit professionals so that they can obtain the necessary understanding of the PCAOB standards. The Cost of Compliance Is Often Underestimated Firms typically budget for registration fees but fail to appreciate the broader financial commitment. Costs frequently include: Upgrades required to firm’s audit methodology Costs to attract and retain experienced personnel Specialized training focused on PCAOB standards Technical accounting resources External consultations Internal inspection programs, that in many instances are outsourced to external consultants with PCAOB inspection experience Quality control enhancements Additional engagement quality reviewers Legal and regulatory support For smaller firms with only a handful of SEC clients, compliance costs can exceed initial expectations and significantly affect profitability. A firm should not ‘dabble’ in the PCAOB arena but should target to grow into this space. Increased Litigation and Regulatory Exposure Becoming a PCAOB-registered firm increases visibility and risk. Public company audits frequently attract: SEC scrutiny PCAOB investigations should a firm have poor inspection results Shareholder litigation when fraud or restatements arise Class-action lawsuits Audit committee scrutiny. Many firms focus on revenue opportunities without fully evaluating whether their risk management framework, insurance coverage, and legal resources are sufficient to support a public-company practice. PCAOB Reporting Requirements Can Be Overlooked Some firms do not recognize the extent of ongoing reporting obligations after registration. Registered firms must file annual reports and timely special reports for specified events. Certain changes which may inadvertently get overlooked involve things like changes to firm ownership, legal proceedings, disciplinary actions against partners, governance matters, or firm leadership may trigger reporting obligations within prescribed deadlines. Failure to maintain accurate and timely reporting can become a regulatory issue independent of audit quality concerns. Audit Committees Expect More Than Technical Compliance Public company audit committees increasingly perform due diligence when selecting auditors and they may consider factors such as: PCAOB inspection history Industry specialization of the firm Staffing models, leverage plans, and the appropriate use of overseas resources Technical resources of the audit professionals Enforcement history Audit quality indicators. A newly registered firm may discover that obtaining registration does not automatically establish credibility in the marketplace. Building a reputation among audit committees can take years. Exit Strategies Are Rarely Considered Few firms consider what happens if they later decide to leave the public company audit market. Exiting the PCAOB environment can also require planning because withdrawal is subject to PCAOB approval and may be affected by pending oversight matters. The PCAOB maintains procedures governing withdrawal requests, and the Board may delay withdrawal while inspections, investigations, or disciplinary matters remain pending. Firms should understand these obligations before entering the regulated environment including if your SEC client needs a consent letter up to 2 years after the firm may have discontinued the relationship with that client. Cybersecurity and Governance Expectations Are Growing Regulatory expectations continue to evolve. Recent PCAOB initiatives, including QC 1000, reflect a more formalized focus on firm governance, risk assessment, monitoring, remediation, and reporting around the quality control system. Firms that view registration as a static compliance exercise may be surprised by expanding disclosure and oversight expectations. As firms become more reliant on technology and external service providers, weaknesses in cybersecurity, data governance, and vendor oversight can become significant regulatory and business risks. Conclusion PCAOB registration can create valuable growth opportunities and enhance a firm's market position. However, registration is only one step in a much broader commitment to audit quality, regulatory compliance, and public accountability. With that being said, most firms do succeed in the PCAOB environment. Typically, it is those firms that evaluate the full lifecycle implications of registration at the outset of their registration. They invest in quality control infrastructure, specialized personnel, independence monitoring, technical training, and governance processes well before accepting their first public company engagement. JGA, with its team of established PCAOB experts, has been able to successfully help many of its clients navigate the risks and shortcomings of firms as they enter the PCAOB space. We can help firms transform their risk profile, operational expectations, and regulatory responsibilities, so that they can gain the reputation and stature of leading audit quality in the PCAOB arena. Note that sources consulted include PCAOB registration and reporting guidance, including Form 1, Form 1-WD, Form 2, Form 3, Form AP, PCAOB inspection priorities and audit committee resources, and PCAOB QC 1000 implementation materials.
July 27, 2026
The Cost of Standing Still: Why Inspection Fear Can Create AI Quality Risk In our recent article AI Governance Belongs in the Boardroom, Not the Server Room , we explained why firm leadership must take responsibility for AI governance rather than treating AI as a technology issue. In When AI Becomes a Quality Risk: Why Governance Alone is Not Enough , we examined what happens when governance exists, but validation, monitoring, implementation, and ongoing evaluation fail to keep pace with adoption. This article examines a different risk: what happens when inspection uncertainty causes firms to delay AI adoption? While caution is appropriate, avoiding AI altogether may preserve the very quality challenges firms are trying to solve. The question is no longer simply whether AI can be used safely. The better question is whether the firm can govern AI use intentionally enough to improve audit quality without creating unmanaged risk. Fear of Inspection Can Become a Quality Management Issue Caution around AI is understandable. Regulators continue to emphasize sufficient appropriate audit evidence, professional skepticism, supervision, documentation, and accountability. AI does not change those expectations, it simply requires firms to demonstrate how AI-assisted work was governed, validated, supervised, and documented. That is why the issue belongs within the system of quality management. AI adoption should not begin with a technology question. It should begin with a quality risk question: where could governed use of AI help the firm respond to recurring quality challenges, and what safeguards must exist before teams rely on the tool? What Inspectors Are Likely to Ask Is Familiar A common misconception is that inspection risk increases simply because a firm uses AI. The more practical risk is that the firm cannot explain how AI use fits within existing audit and quality management expectations. When AI supports audit execution or quality management activities, firms should be prepared to explain: Why the tool was used for a specific audit objective or quality response; How the firm evaluated the reliability, completeness, and relevance of inputs; How outputs were validated before teams relied on them; How professional judgment and skepticism remained central to the conclusion; ·How engagement teams documented AI involvement and related review procedures; and How firm leadership monitored adoption, consistency, exceptions, and emerging issues. They apply existing expectations to a new way of executing or supporting audit work. A firm that can answer them with clarity is better positioned than a firm that avoids formal AI adoption while informal or inconsistent practices develop outside the quality management framework. Avoidance Can Create Its Own Quality Risks Choosing not to adopt AI may feel like the lower-risk path, particularly for engagements subject to heightened regulatory scrutiny. But avoidance does not eliminate quality risk. In some cases, it preserves deficiencies that technology could help address if implemented with appropriate governance, validation, and monitoring. For example, prolonged hesitation may: Limit the firm’s ability to analyze larger or mor complete populations of data; Maintain manual procedures that are difficult to supervise consistently across engagement teams; Delay improvements to methodology, documentation, training, and review practices; Reduce the firm’s ability to respond to recurring inspection or internal monitoring observations; Create uneven practices where some teams experiment informally while others avoid AI entirely; and Make it harder to attract and retain professionals who expect modern tools and clear guidance. The quality risk is not that every firm must immediately deploy AI broadly. The risk is that leadership may mistake inaction for control. If the firm does not define what is permitted, what is prohibited, and what must be validated, teams may fill the gap themselves. Case Study: When Formal Caution Leads to Informal AI Use Consider a firm that has not approved AI for use in audit execution because leadership is concerned about inspection scrutiny. The firm allows AI for general administrative tasks, but it has not issued detailed guidance addressing engagement-level use, documentation expectations, validation requirements, confidentiality restrictions, or supervision responsibilities. At the engagement level, teams continue to face time pressure, complex documentation requirements, and recurring review notes. Some team members begin using publicly available AI tools to summarize contracts, identify potential risk considerations, draft workpaper language, or explain technical accounting concepts. They do so with good intentions and do not view the use as problematic because the firm has not clearly defined boundaries. Several issues emerge: Governance is unclear because no one has formally approved the use case; Validation practices vary by team member and engagement; Supervision does not fully account for AI involvement; Documentation does not explain how AI-assisted outputs were evaluated; Confidentiality and data protection considerations are inconsistently addressed; and Leadership lacks visibility into how broadly AI is being used in practice. The firm intended to reduce inspection risk by delaying adoption. Instead, it created a more difficult risk profile: informal AI use without a consistent governance structure. From a quality management perspective, the issue is not simply that AI was used. The issue is that the firm did not create a controlled path for responsible use. The Better Question: How Should We Govern Responsible Adoption? Progress begins when firms shift the conversation from whether AI should be used to how AI can be governed as part of the system of quality management. That does not mean approving every tool or every use case. It means creating disciplined pathways for evaluating where AI may support audit quality and where the risks outweigh the benefits. Before expanding AI use, leadership should be able to answer: Which AI use cases are approved, restricted, or prohibited? Which quality risks does each approved use case address? What new risks does the use case introduce? What validation is required before outputs can be used? What documentation should appear in the workpapers or quality management records? Who owns the tool, the methodology, the training, and the monitoring process? How will leadership identify inconsistent uses, exceptions, or emerging concerns? These questions make AI adoption more inspection-ready because they connect the technology to governance, methodology, documentation, supervision, and monitoring. They also help firms avoid the false choice between broad, unmanaged adoption and complete avoidance. Inspection Readiness Comes From Control, Not Inaction Inspection readiness does not require firms to wait for AI-specific regulation. It requires firms to demonstrate that AI use remains grounded in existing audit quality principles: accountability, reliable evidence, professional judgment, supervision, and documentation. A governed approach, including approved uses cases, validation procedures, documentation standards, training, and monitoring, allows firms to innovate while maintaining control. Avoiding AI without addressing informal use often leaves leadership with less evidence of control, not more. Key Takeaways Avoidance is itself a governance decision. Existing audit principles, not new AI rules, remain the foundation for inspection readiness. Informal AI use may create greater inspection risk than transparent, governed adoption. Firms should evaluate AI as a quality response, not only as a technology initiative. Responsible adoption requires approved use cases, validation expectation, accountability, training, documentation standards, and ongoing monitoring. Standing still may preserve known quality challenges while allowing uncontrolled AI practices to develop beneath the surface. Final Thoughts The firms that will be most successful in the AI era are unlikely to be those that adopted AI the fastest or avoided it the longest. They will be the firms that can demonstrate thoughtful governance, disciplined implementation, and continuous oversight. Inspection readiness comes from evidence of control, not evidence of hesitation. Johnson Global Advisory supports firms in developing and evaluating AI governance frameworks, including approved use cases, validation practices, documentation standards, monitoring activities, and accountability structures. An independent review can help leadership assess whether the firm’s approach to AI is disciplined, transparent, and inspection-ready without allowing fear of inspection to slow responsible innovation.
Show More