A Master Class on “Audit Quality Control” and “Related Parties and Special Areas” Held at the Chamber of Auditors.

On 17 June 2026, in accordance with the Schedule for Conducting Master Classes Based on Audits Performed by Leading Auditors, approved by Order No. 10-1/3-3-20/2026 of the Chairman of the Chamber of Auditors dated 15 May 2026, an online master class was held on the topics “Audit Quality Control” and “Related Parties and Special Areas”.

At the master class, Gasham Bayramov, Adviser to the Chairman of the Chamber of Auditors on Scientific and Methodological Affairs, acted as moderator, while independent auditor Shamkhal Karimov acted as speaker.

Opening the master class with introductory remarks, Gasham Bayramov, Adviser to the Chairman of the Chamber on Scientific and Methodological Affairs, spoke about the relevance of the topics “Audit Quality Control” and “Related Parties and Special Areas”, as well as the importance of International Standard on Auditing 220 “Quality Control for an Audit of Financial Statements” and ISA 550 “Related Parties”, International Standard on Quality Control 1, and International Standards on Quality Management 1 and 2, emphasizing the need to properly comply with the requirements of the relevant ISAs.

G. Bayramov noted that International Standard on Auditing 220 establishes the auditor’s responsibilities relating to quality control procedures for an audit of financial statements and, where applicable, the responsibilities of the engagement quality control reviewer.

The audit organization is responsible for the quality control system and its related policies and procedures. In accordance with International Standard on Quality Control 1, the organization is required to establish and maintain a quality control system to obtain reasonable assurance that:

-the organization and its personnel comply with professional standards and the requirements of applicable laws and regulations;

-reports prepared by the organization or the engagement partner are appropriate in the circumstances of the particular engagement.

When applying this ISA, the organization must comply with the provisions of International Standard on Quality Control 1 and less stringent national requirements.

Within the organization’s quality control system, engagement teams must perform quality control procedures applicable to the audit engagement and provide the organization with relevant information to enable the operation of the independence-related component of its quality control system.

The auditor’s objective is to implement quality control procedures at the engagement level that provide reasonable assurance that:

  -the audit complies with professional standards and the requirements of applicable laws and regulations;

   -the auditor’s opinion is appropriate in the circumstances of the particular engagement.

The engagement partner is responsible for the overall quality of the performance of each audit engagement assigned to them.

During the performance of an audit engagement, the engagement partner must remain alert, through observation and, where necessary, inquiry, for evidence of non-compliance by members of the engagement team with relevant ethical requirements.

The engagement partner must conclude on compliance with the independence requirements applicable to the audit engagement.

The engagement partner must be satisfied that appropriate procedures relating to the acceptance and continuance of client relationships and audit engagements have been followed and determine whether the conclusions reached in this regard are appropriate.

The engagement partner must be satisfied that the engagement team and any auditor’s experts who are not part of the engagement team have the appropriate knowledge and skills to:

-perform the audit engagement in accordance with professional standards and applicable legal and regulatory requirements;

-ensure the preparation of an auditor’s report appropriate to the terms of the audit engagement.

The engagement partner must assume responsibility for:

-the direction, supervision and performance of the audit engagement in compliance with professional standards and the requirements of applicable laws and regulations;

-the preparation of an auditor’s report appropriate to the circumstances of the audit engagement.

The engagement partner must assume responsibility for ensuring that reviews are performed in accordance with the organization’s review strategy and procedures.

The engagement partner:

-must be responsible for the engagement team’s consultations on difficult or contentious matters;

-must be satisfied that members of the engagement team have undertaken appropriate consultation during the performance of the engagement, both within the engagement team and between the engagement team and others within or outside the organization;

-must be satisfied that the nature and scope of such consultations and the conclusions resulting from them have been agreed with the consultant;

-must determine that the conclusions resulting from such consultations have been implemented in practice.

When auditing the financial statements of listed entities, as well as when performing audit engagements for which the organization has determined that an engagement quality control review is required, the engagement partner:

-must determine the appointment of an engagement quality control reviewer;

-must discuss significant matters arising during the performance of the audit engagement, including those identified during the engagement quality control review, with the engagement quality control reviewer;

 -must not set a date for the auditor’s report until the engagement quality control review has been completed.

  The engagement quality control reviewer must objectively evaluate the significant judgments made by the engagement team and the conclusions reached in forming the auditor’s report.

An effective quality control system includes a monitoring process designed to provide reasonable assurance that the organization’s policies and procedures relating to its quality control system are relevant, adequate and operating effectively. The engagement partner must consider the findings of the organization’s monitoring process and, where applicable, those of other network firms, evidenced in the latest circulated information memorandum, and whether the deficiencies identified in that memorandum may affect the audit engagement.

The auditor must include the following in the audit documentation:

-identified issues relating to compliance with relevant ethical requirements and how they were resolved;

-conclusions on compliance with the independence requirements applicable to the audit engagement and the conclusions of any consultations with the organization supporting these conclusions;

-final conclusions reached regarding the establishment and maintenance of client relationships and the acceptance and performance of audit engagements;

-the nature and scope of consultations undertaken during the performance of the audit engagement, together with the conclusions reached on their basis.

International Standard on Auditing 550 “Related Parties” establishes the auditor’s responsibilities relating to relationships and transactions with related parties during the audit of financial statements.

Many transactions with related parties occur in the normal course of business. In such circumstances, the risk of material misstatement of the financial statements associated with such transactions is not necessarily higher than for similar transactions with unrelated parties. However, in certain circumstances, the nature of relationships and transactions with related parties may give rise to a higher risk of material misstatement in the financial statements than transactions with unrelated parties.

Because related parties are interdependent, many financial reporting frameworks establish specific requirements for the accounting for and disclosure of relationships, transactions and balances with related parties so that users of financial statements can understand their nature and their actual or potential effects on the financial statements. Where such requirements are established in the applicable financial reporting framework, the auditor must perform audit procedures to identify and assess the risks of material misstatement arising from the entity’s failure to comply with requirements relating to the accounting for or disclosure of relationships, transactions and balances with related parties, and to take appropriate responsive actions.

Even if the applicable financial reporting framework has no requirements relating to related parties (or has only minimal requirements), the auditor must perform sufficient analysis of relationships and transactions with related parties to reach conclusions regarding the financial statements (if they relate to such relationships and transactions):

-whether fair presentation of the financial statements has been achieved (from the perspective of fair presentation frameworks);

 

-whether the financial statements could mislead users (from the perspective of compliance frameworks).

The requirements of this ISA are designed to assist the auditor in identifying and assessing the risks of material misstatement associated with relationships and transactions with related parties and in designing audit procedures to respond to the assessed risks.

The auditor’s objectives are:

      1)To obtain sufficient understanding of related party relationships and transactions, irrespective of whether the applicable financial reporting framework establishes requirements relating to related parties, for the purposes of:

-identifying, where applicable, fraud risk factors that are significant to the identification and assessment of the risks of material misstatement due to fraud arising from relationships and transactions with related parties;

-based on the audit evidence obtained, reaching conclusions regarding the financial statements (if they relate to such relationships and transactions):

-whether fair presentation of the financial statements has been achieved (under a fair presentation framework);

-whether the financial statements could mislead users (under a compliance framework);

2)In addition, where the applicable financial reporting framework establishes requirements relating to related parties, to obtain sufficient appropriate audit evidence about whether relationships and transactions with related parties have been appropriately identified, accounted for and disclosed in the financial statements in accordance with the applicable framework.

G. Bayramov gave the floor to Sh. Karimov to make a detailed presentation on these topics. Speaking on the subject, Sh. Karimov noted that quality control inspections conducted in recent years show that the majority of deficiencies identified in audit files are related specifically to quality management. In this presentation, we will discuss the theoretical foundations of audit quality, practical deficiencies and how a high-quality audit file should be structured.

When discussing audit quality, auditors first think of ISA 220. However, audit quality is not the subject of only one standard — it is an integrated system in which three standards work together.

ISQM 1 — Firm Level

Regulates quality management at the audit organization level. The main objective of the standard is to establish a system within the audit organization that ensures audit engagements are performed in accordance with professional standards and legal requirements.

ISA 220 — Engagement Level

If ISQM 1 establishes the quality system at the firm level, ISA 220 determines how that system should be applied to a specific audit engagement. In other words, ISQM 1 establishes the organization’s quality system, while ISA 220 implements that system in a specific audit file.

 

 

ISQM 2 — Engagement Quality Review

Establishes the mechanism for an independent quality review of certain audit engagements. This standard serves as an additional safeguard mechanism, particularly in audits of public interest entities and high-risk engagements.

One of the most important features of ISQM 1 is the application of a risk-based approach. Whereas the previous approach focused primarily on the existence of policies and procedures, the new approach is based on identifying and managing quality risks. The firm first establishes quality objectives, then assesses the risks that may prevent those objectives from being achieved and develops responses appropriate to those risks.

In fact, this logic is very familiar to auditors — we see the same approach in ISA 315. Just as we identify risks of material misstatement in financial statements during an audit, under ISQM 1 the audit organization must identify quality risks.

The main idea of ISA 220 is that audit quality does not occur by chance. Quality must be planned, managed and documented. The standard places overall responsibility for audit quality on the engagement partner.

The engagement partner may distribute work among team members, but cannot delegate overall responsibility for quality. This responsibility remains with the engagement partner until the end of the audit.

ISA 220 identifies six key components of audit quality. These components are not separate elements operating independently — together they form an integrated system and serve to properly manage audit risks.

ISQM 2 acts as the final line of defense in this system. Auditors sometimes regard a quality review as an additional audit procedure. In fact, the purpose of ISQM 2 is not to perform the audit again. The engagement quality reviewer does not perform procedures on behalf of the audit team. Their role is to independently and objectively evaluate significant judgments, significant risk areas and the appropriateness of the auditor’s opinion to be issued.

Experience shows that the same deficiencies recur in different audit organizations. Most of these deficiencies arise not from a lack of technical knowledge, but from a weak methodological approach.

Deficiency 1 — Risk assessment is formal in nature (ISA 315).

Risks are recorded in the audit file, but those risks do not arise from the activities of the specific entity.

Deficiency 2 — No link is established between risks and audit procedures.

A risk is identified, but the audit procedure responding to that risk cannot be seen.

Deficiency 3 — Evidence exists, but the auditor’s conclusion is not visible (ISA 500).

Sometimes an audit file contains numerous documents: bank confirmations, contracts and calculations. However, there is no auditor conclusion.

Deficiency 4 — Materiality is determined but not used throughout the audit (ISA 320).

Materiality is calculated, a working paper is prepared, and percentages and amounts are indicated. However, materiality is not used at subsequent stages: sometimes the sample size is not linked to materiality, sometimes identified misstatements are not compared with materiality, and sometimes materiality is not considered at all in the final assessment.

Deficiency 5 — Professional skepticism is not visible in the audit file (ISA 200).

 Risks are recorded in the audit file, but those risks do not arise from the activities of the specific entity.

Deficiency 6 — Excessive reliance on management’s representation letter (ISA 580).

Sometimes auditors accept management’s representation letter as the main piece of evidence. However, a representation letter does not replace other audit evidence — it complements the other evidence obtained by the auditor. If an auditor relies solely on management’s representation regarding a significant matter, this creates a risk from an audit quality perspective.

 

 

Deficiency 7 — Weak justification of external confirmation procedures (ISA 505).

Sometimes, despite significant receivables and payables, external confirmation procedures are not performed, or the reason for not performing them is not justified in the audit file. In other cases, confirmation letters are sent and responses are received, but differences are not analyzed and discrepancies are not investigated.

Deficiency 8 — Weak link between the auditor’s opinion and the audit file (ISA 700).

The auditor’s opinion is the final result of the audit process. Therefore, the opinion should be the logical continuation of the conclusions documented in the audit file.

Practical Recommendations

Start the audit with risks, not standards.

-Before preparing the audit program, try to understand the entity. How does the entity generate revenue? What are the main risks? Where could a material misstatement arise in the financial statements? A good audit program comes from risk assessment, not from a template.

The auditor’s thinking should be visible in the audit file.

-The number of documents collected is not a measure of quality. The key issue is to show how the auditor arrived at a particular conclusion. A person reading the audit file should be able to follow the auditor’s logic. Professional judgment and professional skepticism should be visible not only in the auditor’s mind, but also in the audit documentation.

The role of the engagement partner should not be merely formal.

 -The engagement partner is not merely the person who signs the auditor’s opinion. They must actively participate in developing the audit strategy, assessing significant risks, resolving complex matters and forming final conclusions. In a high-quality audit file, the engagement partner’s involvement should be evident.

Build quality at the beginning, not at the end of the audit.

-Quality does not arise at the final review stage. Quality begins with client acceptance. Team selection, time planning, resource allocation and risk assessment form the foundation of audit quality. Correct decisions made at the beginning of the audit prevent many problems at later stages.

Treat quality control as an opportunity for development.

-The purpose of quality control is not to punish the auditor or look for deficiencies. The main objective is to contribute to the development of the profession, improve audit quality and strengthen confidence in financial statements. Every inspection is also an opportunity for the auditor to learn and improve.

Related parties and special audit areas. These topics are not brought together by chance — they have a common feature: all are characterized by high inherent risk, high uncertainty and susceptibility to management influence. Quality control inspections show that auditors face the greatest difficulties precisely in these areas and that the most serious deficiencies arise here.

The reason these areas are called “special” is that standard, mechanical procedures are not sufficient here. A figure may appear correct, a document may exist, but the real questions are different: why did this transaction actually occur, how reliable is this estimate, and has this relationship been properly disclosed? All of this requires professional skepticism.

Identification of Related Parties

The logic of ISA 550 can be summarized in three questions: who are the related parties (identification), what transactions have taken place with them and are these transactions normal (substance and terms), and have these relationships and transactions been properly accounted for and disclosed (accounting and disclosure). A key to remember: the three key words of related party auditing are WHO (relationship) → WHAT (transaction and terms) → how disclosed.

The key principle: identifying related parties does not end with the list provided by management. The auditor should seek confirmation from independent sources (registration records, bank information, minutes, contracts). The chain is: identify related party transactions → assess the terms → investigate the business rationale → verify accounting and disclosure → report to management.

Accounting Estimates — ISA 540

An accounting estimate is inherently uncertain. ISA 540 requires estimates to be assessed using three inherent risk factors: estimation uncertainty, complexity and subjectivity. Subjectivity opens the door to management bias. The auditor should first understand how the entity calculates the estimate and then respond accordingly.

Three possible approaches

1.Test management’s process.

-Test how management prepared the estimate — verify assumptions, methodology and data sources.

2.Develop the auditor’s own range.

-Develop the auditor’s own point estimate or range and compare it with management’s result.

3.Subsequent events.

-Obtain evidence from events that occurred up to the reporting date.

Finally, there is the “stand-back” requirement: the auditor evaluates whether the evidence obtained supports the estimate as a whole and whether the disclosure is adequate.

Selected Items — ISA 501

ISA 501 requires additional procedures in three specific areas. Each of these areas carries particular risks, and standard audit procedures are not sufficient.

Inventories

When material, the auditor participates in the physical inventory count — evaluates the inventory count instructions, observes the count and performs test counts. If participation is not possible, alternative procedures are applied and the reason is documented. As a result, direct evidence of the existence of inventories must be obtained.

Litigation and Claims

Inquiry of management, review of minutes and legal expenses, and, where there is a risk, direct correspondence with the entity’s external legal counsel. Undisclosed claims may create hidden liabilities. The auditor cannot rely solely on management’s explanations.

Segment Information

Understand the methods used by management and test their application. Proper preparation and disclosure of segment information should be a key focus of the auditor.

Going Concern — ISA 570

Going concern is not merely a formal check. The auditor reviews management’s assessment, identifies events and conditions that may cast significant doubt on going concern and, where such doubt exists, evaluates whether a material uncertainty exists and whether the disclosure is adequate. In practice, going concern problems often become apparent first not from the financial statements themselves, but from cash flows, credit obligations, tax liabilities and delays in payments to suppliers.

Most Common Deficiencies

Let us look at the most common deficiencies identified in these areas during quality control inspections. You will see that most of them arise not from a lack of technical knowledge, but from weak professional skepticism and insufficient documentation of the rationale.

1. Related parties are identified only based on management’s list (ISA 550).

2. The claim that a transaction is “at market terms” is accepted without justification (ISA 550).

3. The business rationale of a significant transaction is not assessed (ISA 550 / 240).

4. An estimate is accepted as management’s figure (ISA 540).

5. The auditor does not participate in the physical inventory count (ISA 501).

6. No correspondence is conducted with legal counsel regarding litigation (ISA 501).

7. Going concern is assessed formally (ISA 570).

8. Disclosures are not checked (ISA 550 / 540 / 700).

9. Indicators of undisclosed related parties are not investigated (ISA 550).

 

 

Practical Recommendations

-Independently confirm related parties.

-Management’s list is a starting point, not the endpoint. Compare it with registration records, bank information, minutes and contracts.

-Ask “why?” for every significant transaction.

-Investigate the economic rationale of a related party transaction outside the normal course of business. If the rationale is unclear, consider the possibility of fraud.

-In these areas, disclosure is not a formal text created at the end of the audit; it is part of the planning process.

-Treat the estimate as a process.

-Assess the estimate not merely as a figure, but in terms of assumptions, uncertainty and possible bias. Develop a range where necessary.

-Plan disclosures in advance.

-Show skepticism in the file.

-In these areas, professional skepticism is the core of the audit — and it must be visible not only in the auditor’s mind, but also in the audit file.

Conclusion:

Related parties and special areas are areas of the audit involving a “high degree of judgment”. Quality in these areas is built on the following: independent identification of related parties; assessment of the business rationale of significant transactions; testing estimates as processes involving uncertainty; direct evidence for selected items (inventory counts, legal correspondence); assessment of going concern and adequacy of disclosures; strong professional skepticism and clear documentation. Ultimately, high quality in these areas depends not on checking figures alone, but on independently and skeptically evaluating management’s judgments and documenting that evaluation.

The master class continued with practical discussions, and participants’ questions were answered.

Nearly 100 members of the Chamber of Auditors participated in the master class.

Related Parties and Special Areas (PRESENTATION)

Audit Quality Control (PRESENTATION)

 

Chamber of Auditors of the Republic of Azerbaijan