Overview
To support our commitment to transparency and audit quality, we have prepared a transparency report for 2025‒26 to provide insights into the way we audit and apply our internal practices.
This transparency report outlines our approach to quality management practices and how we assess risks to audit quality.
Published 9 October 2026.
Summary
This report supports transparency about how we manage audit quality at the Queensland Audit Office (QAO). It outlines our approach to quality management practices and how we assess risks to audit quality. We report on areas of strength and where we can improve, supporting confidence in our work.
QAO is accountable to the Queensland Parliament as its independent auditor of all public sector and local government entities. We provide financial and performance audits and sustainability assurance, and report results and insights to parliament.
We apply the Auditor-General Auditing Standards and other relevant auditing standards to our work. We deliver more than just an audit or assurance report – our work goes to the heart of delivering better public services and focuses on probity and propriety of decision-making, accountability, and value-for-money to the public.
This transparency report covers our audit quality program for the year ended 30 June 2026. We choose to provide this report to:
- explain our quality program and results
- show how we seek to improve our audit and assurance practices
- describe our system of quality management.
The content of this transparency report is guided by the Corporations Act 2001 for auditors of listed entities. We have voluntarily adopted these requirements in the public sector to demonstrate and support transparency of our audit practices.
Transparency at a glance
Our transparency report also includes 10 audit quality indicators, providing useful quantitative insights into our engagement processes. In 2025–26, we either achieved the target or were within 10 per cent of meeting the target in all of these indicators.
Confidentiality and protecting information
Protecting confidential information remains a core responsibility of QAO. We are committed to continually improving our governance arrangements and practices to maintain the integrity, confidentiality, and security of information entrusted to us. We regularly review and strengthen our internal policies, procedures, and controls to support the secure management of sensitive information.
Section 53 of the Auditor-General Act 2009 (AG Act), applying to QAO employees and audit service providers (ASPs), imposes significant penalties for the inappropriate disclosure of protected information.
In late 2024–25, we enhanced our contractual requirements with ASPs to require formal acknowledgement of their obligations under the AG Act, and to confirm each audit year that they have not breached these obligations. This year we wrote to certain ASPs to promptly address potential confidentiality matters and seek their written assurances that they had complied with the requirements of the AG Act. Those ASPs confirmed that they had not breached our, or our clients’, confidentiality.
Non-assurance services
We prohibit ASPs from delivering non-assurance services to their QAO audit clients without the Auditor‑General's approval. We only approve non-assurance services in limited circumstances. ASPs must ensure that the Auditor-General is advised of any real or perceived conflicts of interest in relation to work undertaken on behalf of the Auditor-General. We explain this further in Chapter 2.
Our system of quality management
Our system of quality management is designed to support consistent quality in all audits and assurance engagements. In line with ASQM 1 Quality Management for Firms that Perform Audits or Reviews of Financial Reports and Other Financial Information, or Other Assurance or Related Services Engagements (ASQM 1), we apply a risk-based approach to identify and address risks to achieving quality.
We undertake a root cause analysis of quality issues identified through our monitoring program and for all significant errors identified in our clients’ prior financial statements.
Our audit quality program monitors all financial audits, performance audits, and assurance reviews. The results support our conclusion that our system of quality management is functioning effectively. We perform reviews of finalised engagement files, in-progress engagement files (known as open file reviews), and systems of quality management of our ASPs (firm reviews). The results of our monitoring include:
Engagement file reviews
| |
Open file reviews
| |
Firm reviews
|
Quality management and our office
Quality management is a part of everything we do and reflects our commitment to delivering reliable and independent audits. It gives us confidence that our work supports better public services and sound financial management.
Through our quality reviews, we support our people to grow their professional skills and make informed judgements. By focusing on quality, we ensure trust in our reports and the advice we give to parliament and the public sector.
Our Strategic Plan 2026–2030 outlines our objectives, risks, organisational strategies, and indicators of achievement, aligned to our vision and purpose. The plan is founded on our understanding of the needs and expectations of our clients, our stakeholders, and the broader community. It provides an overarching framework and sets the strategic direction for our operational and workforce planning, forward work plan, and service delivery statement. It guides how we prioritise resources, deliver valued services, and measure our performance.
| Trusted and impactful work – We foster trust through products, advice, and engagements that add value. We continue to strengthen our systems and practices to support transparency, clear decision-making, and quality outcomes across all audit activities. | |
| Capable and empowered people – We invest in our people and culture to maintain a workforce that meets our needs. We have embedded a culture of continuous improvement that reflects our values. We provide operating structures and programs that grow the capability of our workforce. We continue to grow our staff by refining training, on-the-job learning, and methodology and guidance, while promoting skills and capability through strong leadership and clear frameworks. | |
| Contemporary, quality audits – We embrace innovation and evolve our systems, tools, and ways of working. Engagement leaders and staff continue to meet high professional standards, demonstrating our commitment to quality. This includes providing them with contemporary, up-to-date methodologies, and our teams applying them consistently and taking responsibility for the outcomes of each engagement. This includes our artificial intelligence (AI) journey, ensuring we have appropriate governance in place before we incorporate it into our systems and practices. |
Sustainability assurance engagements
The Australian Government requires large public companies to prepare climate-related financial disclosures and have them assured for the first time for 2025–26. Nine large government companies prepared these reports for 2025–26.
We developed a sustainability methodology that complies with ASSA 5000 General Requirements for Sustainability Assurance Engagements. We held several training sessions throughout the year and convened regular working group meetings to build staff capability, support consistent application of the sustainability assurance methodology, and address emerging interpretation and practice issues. We undertook 3 open file reviews. The results indicate compliance with our methodology, and a good understanding of how to deliver the limited assurance conclusion. We used the results to refine our training, methodology and testing templates.
Statement on the effectiveness of our system of quality management
The Australian Securities and Investments Commission (ASIC) Information Sheet 184 summarises the audit transparency report requirements under sections 322 to 332G of the Corporations Act 2001. These requirements do not apply to QAO. However, as a public sector equivalent of an audit firm, we choose to adopt them voluntarily where relevant and appropriate to our role.
I have evaluated our system of quality management, and the results provide me with reasonable assurance to conclude that:
- our system of quality management functioned effectively in 2025–26
- in accordance with Auditor-General Auditing Standards, which incorporate ASQM 1 Quality Management for Firms that Perform Audits or Reviews of Financial Reports and Other Financial Information, or Other Assurance or Related Services Engagements, we are achieving our quality management objectives, as described in this transparency report.
The audits we deliver are supported by an effective internal quality management system.
Rachel Vagg
Auditor-General
October 2026
1. Our quality results
Our system of quality management supports consistent quality in all audit and assurance engagements. It is designed to meet the requirements of:
- ASQM 1 Quality Management for Firms that Perform Audits or Reviews of Financial Reports and Other Financial Information, or Other Assurance or Related Services Engagements (ASQM 1)
- ASQM 2 Engagement Quality Reviews (ASQM 2).
How we evaluate quality
ASQM 1 requires a risk-based approach to designing, implementing, and operating a quality management system. The system should be connected and coordinated in a way that supports proactive management of engagement quality. It also requires QAO to evaluate its system annually and conclude whether it provides reasonable assurance that quality objectives are met.
We found QAO’s system of quality management provided reasonable assurance it achieved its quality objectives. The evaluation confirmed that risks were managed appropriately, and the system was operating effectively.
We are committed to delivering audit quality and use our annual quality review program to assess audit engagements by our staff and ASPs. The program helps us understand common findings and areas where quality does not meet expectations, and informs our learning, support materials, and resourcing.
Our annual quality assurance plan sets out the engagement files for review and key focus areas. It is endorsed by the Executive Leadership Team and approved by the Auditor-General. We select files based on judgement, considering risk, complexity, and prior quality issues. We review more financial audit files than performance audit files due to their size and number.
Engagement file reviews | Open file review |
|---|---|
| Our quality reviews of engagement files check if audits follow our methodology and relevant standards. An independent reviewer assesses if the audit team obtained enough evidence to support its judgements, conclusions, and audit opinion. An engagement is selected for each financial audit engagement leader every year unless they are provided an exemption (see below). We also review engagements by partners at our ASPs every 1–3 years. We select an engagement for each performance audit engagement leader each year. | An open file review is completed before the audit is finalised. It helps identify issues early so corrective action can be taken. These reviews focus on audit strategies that may affect the audit opinion, inefficient approaches, and how data analytics is used. They also check whether changes in auditing standards or better practices have been applied. We review one engagement for each internal engagement leader every year after their planning has been completed. We also do open file reviews over internal or ASP engagement files that were rated unsatisfactory in the prior year. We may undertake an open file review where an ASP partner is undertaking audits for us for the first time, or where they are auditing in an industry for the first time. |
ASQM 1 review | Root cause analysis |
|---|---|
| ASQM 1 requires the Auditor-General to evaluate, on behalf of QAO, the system of quality management annually, at a set point in time. This includes reviewing our governance, policies, procedures, and guidelines for consistency with ASQM 1. We assessed the completeness of our quality objectives, risks to achieving them, and the effectiveness of our risk treatments. We also undertook rotational controls testing to confirm they worked as intended. | Root cause analysis is a process used to identify the key causes behind significant quality findings, policy breaches, or positive audit outcomes. It supports actions to prevent future issues and promote good practices. Root cause analysis is applied when serious audit deficiencies, material errors, or repeated issues arise. Findings are used to improve our practices and inform our training. |
Queensland Audit Office.
Our quality results and what we learnt
Our audit quality program monitors all financial audits, performance audits, and assurance reviews. The results support our conclusion that our system of quality management is functioning effectively.
Engagement file reviews and open file reviews
The following table details the results of engagement reviews.
Financial audit engagements | |
|---|---|
Engagement file reviews We reviewed 29 closed files’ financial audit engagements. Eleven of 12 reviews of in-house files were satisfactory. No engagement leaders were exempt from review this year. The satisfactory audits met our quality expectations with no significant issues identified. One file did not meet our quality expectations. We acted on these results. Our response is explained in the Responding to audit quality findings section. We also reviewed 17 files from our ASPs, all of which met our quality expectations. We required a partner rotation for one audit engagement due to concerns about whether the ASP partner met our requirements to be registered with QAO. As a result of the partner change, we undertook an open file review of the audit file for 2025. | |
Open file reviews We undertook open file reviews over the planning stage of 10 in-house financial audits. We assessed these against 36 quality indicator metrics, and the overall average compliance was 75 per cent. As these open file reviews are early in the audit, and only cover planning, we do not rate the results. This is because the audit teams can address any weaknesses before the audit is completed. The quality indicator metrics confirmed several areas in planning documentation that had been satisfactorily undertaken. Areas needing to be addressed included consistency between the testing program and the risk response programs, including identification of key controls and completion of various areas by the preparer and review by a senior member of the engagement team. A thematic review report is provided to all financial audit engagement teams to consider the implications for their audits. We performed an open file review of one file originally selected for an engagement review, using our engagement file audit quality program. We did this because the financial statements had not been signed by the client at the time the review was undertaken. The review was found to be satisfactory with minor improvement findings. We reviewed 3 open files of clients performing sustainability reporting in 2026 over the course of the assurance engagement. This was to support quality and effective delivery, and ensure our new methodology was fit-for-purpose. We discussed the findings with all sustainability assurance teams to share the learnings in real-time. We also completed 3 open file reviews on ASP engagements. We performed one review over a partner who had not carried out audit engagements for QAO before, and 2 were in response to concerns with audit quality from the prior year. | |
Performance audit engagements | |
|---|---|
Satisfactory engagement file reviews We completed 3 engagement file reviews for performance audits, all of which were satisfactory. This result indicates ongoing compliance with audit standards during the audit process, supporting the delivery of high-quality reports to Parliament. | |
Firm reviews | |
|---|---|
ASP firm reviews Our ASPs are part of our system of quality management, and they deliver audits on our behalf using their own audit methodology, systems, and staff. It is important to us, and our clients, that their systems of quality management are robust and meet the expectations set out in the Auditor-General Auditing Standards. The firms are required by their own quality responsibilities to assess the operating effectiveness of their quality management systems for the entire firm. However, we appropriately only review our ASPs’ systems of quality management to the extent that they are relevant to performing audits on our behalf. We assess whether the ASP firms have addressed the requirements of ASQM 1, ASQM 2, and APES 325 Risk Management for Firms. We also assess whether firms have implemented sufficient appropriate quality processes as required by the Auditor-General Auditing Standards, professional standards, and regulatory and legal requirements. To the extent they are relevant to performing audits on our behalf, we evaluated the systems of quality management at 5 of our ASPs. For the other 8, we performed reviews to understand changes in the firms’ approaches to quality management and changes to their methodologies. We rated all firms as having satisfactory systems of quality management as they related to performing work for us. We made 13 recommendations on quality matters to 4 ASPs and re-raised 3 recommendations at another ASP to further strengthen and improve their systems. The Australian Government’s Parliamentary Joint Committee on Corporations and Financial Services is considering one firm for improper use of private sector clients’ audit information. We incorporated these matters into our review of the firm’s system of quality management and wrote to them about understanding any potential impact on QAO and our clients. This is explained further in Chapter 2 under Managing Information. In 2024–25, we identified one firm requiring significant improvements in oversight and supervision of its engagement leaders and engagement files. We had in-depth discussions with the managing partner about quality matters and our expected improvements. In response, in 2025–26, we decreased the number of audits contracted to this firm and increased our supervision and oversight. Our responses are detailed in the Responding to audit quality findings section below. | |
Responding to audit quality findings
QAO’s Quality Management Committee:
- moderates all reviews where the quality assurance reviewer is recommending an unsatisfactory outcome
- assesses the findings from the root cause analysis
- determines a response.
Unsatisfactory results
One in-house file did not meet our quality expectations. This was primarily due to lack of timely review undertaken by the engagement leader and engagement quality reviewer. There was also insufficient audit work carried out over the completeness and accuracy of property, plant and equipment contributed to the entity.
In response to this outcome, the committee assigned a more senior engagement leader as a signing officer to all larger or higher-risk audits undertaken by the engagement leader. This is to provide quality management support. The insufficient work on the client was also re-performed this audit cycle to ensure there wasn’t a prior period error in the financial statements.
A performance and training program has been established for the engagement leader and engagement quality reviewer.
Quality assurance program results
The number of issues raised this year is 10 per cent below the previous 3-year average. However, compared to last year, we had a 15 per cent increase in moderate and high-risk issues identified in our 29 engagement file reviews. In-house audits accounted for 55 per cent of the moderate and high-risk issues from the engagement reviews. Audits delivered by our ASPs had a reduction in issues from 69 per cent in 2024–25 to 45 per cent in 2025–26.
We did not identify any instances where there is evidence that the engagement leader issued an incorrect audit opinion.
Many quality findings relate to more complex areas of audit work including property, plant and equipment, information systems, and revenue. These more complex areas of work require high levels of technical competency, more senior staff involvement, and a greater level of supervision and review.
Our quality findings in identifying risks and/or developing risk response mostly relate to staff skills in these areas, and the underpinning audit technical training and audit programs.
We also found that supervision and direction have not always ensured that assigned tasks and responsibilities have been carried out by the appropriate team members, and that documentation to support our judgements is sufficient.
These findings are mostly being addressed through:
- enhancing the mix of resources and capabilities on these engagements
- refining training programs and having staff attend additional training
- acting on individual engagement files, with more timely supervision and review supported by engagement leaders and engagement managers better managing their time
- reflecting positive and negative quality assurance results into performance plans to encourage positive quality behaviours
- providing audit staff with audit tools for complex areas.
Prior period errors
Potential errors in published financial statements are sometimes identified by financial statement preparers or their auditors in a subsequent year. Prior period errors occur when financial statements from past years contain significant omissions or misstatements. These errors are corrected in the current year’s statements when they are of such importance in dollar value or context to the entity’s operations that users of the financial statements may be misled.
Our Modified Opinions Panel considers:
- whether an identified matter is an error
- if it is an error, whether it is significant enough to warrant correction in the current year
- the root cause of the previous audit team not identifying the error.
During the 2025–26 financial year, we recorded 12 prior errors from the 414 audit opinions we issued (2.9 per cent). We performed a root cause analysis on these 12 errors, which were mainly for complex areas such as property, plant and equipment, including contributed assets at local governments, and revenue recognition.
The results of the root cause analysis are reported semi-annually to the Executive Leadership Team. Findings are analysed to determine the most appropriate future actions, including resourcing decisions, updates to testing programs, and more targeted training.
We discuss our findings with our ASPs at our regular ASP forums and specific sector forums. We also invite our ASPs to attend our training sessions where applicable.
Sustainability assurance engagements
The Queensland Government has 9 large companies that prepared climate-related financial disclosures for the first time in 2025–26. Entities within scope must prepare a sustainability report that complies with Australian Sustainability Reporting Standards issued by the Australian Accounting Standards Board, and obtain independent assurance over their climate-related financial disclosures.
We undertook several actions to ensure our staff were well prepared and equipped, including:
- convening regular working group meetings, chaired by a senior engagement leader with audit clients preparing reports for the first time
- holding several training sessions throughout the year for all staff working on these engagements
- undertaking 3 open file reviews
- reflecting on the learnings and feedback from the above actions to refine our methodology, templates, and training.
Our approach supported consistent application of the methodology, and addressed emerging interpretation and practice issues.
We identified areas of sound practice but also areas where further guidance and capability development will support consistent high-quality assurance outcomes.
We held sustainability workshops with our clients who were required to report in 2025–26, and also provided regular updates in our various forums during the year. In our specific energy industry forum, we included a session on sustainability and discussed the type of evidence we would be examining as part of these assurance reviews.
Strategic review of the Queensland Audit Office
A key accountability measure is an independent review (strategic review) of our organisation, conducted at least every 5 years. The Queensland Governor in Council appoints independent reviewers from outside QAO and provides them with the terms of reference. The reviewers engage with us, our staff, our clients, and other key stakeholders to understand how well we are operating and fulfilling our mandate.
The last strategic review report, Strategic Review of the Queensland Audit Office 2023, was tabled in parliament on 15 February 2024. It concluded that QAO’s functions are effective, efficient, economic, and valued. The review also identified opportunities for improvement. Its results and our response are published on our website at www.qao.qld.gov.au/about-us/external-reviews.
In our Annual report 2025–26, we discussed our progress in addressing the reviewers’ recommendations. We are making good progress on the 10 recommendations relating to audit quality, having closed 8. Our internal auditors validate that our responses have been effectively implemented before we close a recommendation.
What are we doing to improve and maintain audit quality?
Quality assurance findings inform our improvement actions We undertake root cause analysis for all significant quality issues, including material prior period errors. These results, and the results of our quality reviews, inform us about areas we need to invest in to support and improve the skills of our audit staff and ASPs. Our 2026–27 training program will focus on efficient audit practices that improve our quality by:
| |
Monitoring our indicators of audit quality We monitor audit quality using 10 key indicators. These include 6 indicators from the Australasian Council of Auditors-General (ACAG), which provide comparable information for audit offices across Australia. We monitor the indicators monthly throughout the audit year. They help us track performance, guide targeted training and improvements, and inform our resource needs. This approach provides insights to adjust our practices and enhance audit outcomes. Details of the indicators are in Appendix B. | |
Actions we are taking to improve audit quality in 2026–27 Based on the 2025–26 findings, we will deliver improvement actions to support our financial, performance, and assurance audits, including those conducted on our behalf by ASPs. Key actions include:
|
Our action on commitments from last year
Figure 1B provides an acquittal of the commitments we made in our Transparency report 2024–25.
Commitment | Status |
|---|---|
| Present engagement file reviews and root cause analysis findings to staff and ASPs in audit update sessions |
Note 1 |
| Update training plans, templates, and methodology to address key issues | |
| Deliver targeted quality assurance workshops to ASPs |
Note 1 |
| Enhance sector engagement and communication with ASPs |
Note 2 |
Note 1: We hold annual ASP forums in Brisbane and Cairns, where we present and discuss quality assurance findings.
Note 2: Our industry leads run forums with ASPs on industry-specific matters. These are held at key points in the audit cycle to discuss common risk assessments, risk responses, and areas of audit focus. Our industries include energy, water, health, local government, and universities.
2. Our system of quality management
Our system of quality management supports consistent quality in all audit and assurance engagements. This chapter describes the components of our system; Chapter 1 evaluates its effectiveness.
The Australian Standard on Quality Management (ASQM 1) requires audit firms to design, implement, operate, and regularly evaluate their system of quality management. A compliant system of quality management addresses the 8 components shown in Figure 2A.
Queensland Audit Office from ASQM 1.
Our risk assessment process
Our approach
In accordance with ASQM 1, we apply a risk-based approach in designing, implementing, and operating the components of our system of quality management, including:
- establishing quality objectives specified by ASQM 1
- assessing whether we need to establish any additional objectives to achieve the aims of our system of quality management. We concluded we did not need to establish additional objectives
- identifying and assessing risks to achieving the quality objectives (quality risks). We review these risks regularly throughout the year
- designing and implementing responses to address the quality risks, including controls or treatments in place to prevent occurrences and/or minimise consequences if a risk occurs.
In applying this approach, we consider the nature and circumstances of the engagements we perform and our role as Queensland’s independent public sector auditor.
Our culture of quality
We promote a culture of quality, risk awareness, and consultation. Quality and risk are regular agenda items at Executive Leadership Team meetings and Audit and Risk Management Committee meetings.
We undertake quarterly reviews to assess and adjust risk management. This ensures our approach to risk is contemporary with our operating environment.
Our culture encourages learning from quality review findings by sharing insights and updating methodologies and training annually. Performance assessments include audit quality, with staff evaluated annually on their commitment to quality, risk management, client service, mentoring, and contributions to audit quality initiatives.
Our Head of Quality is supported by a team to carry out the quality assurance program for the year, technical training, and methodology support.
Governance and leadership
Our structure is designed to support quality by providing clear leadership, defined roles, and effective oversight of our quality processes.
Our quality management structure is outlined in Figure 2B.
Queensland Audit Office.
The Executive Leadership Team, which includes the Auditor-General, leads the system of quality management, supported by the committees and panels outlined in the Governance and oversight bodies section below. This structure helps us apply a consistent approach to audit quality, support sound decisions, and respond to risks in a timely way.
Governance and oversight bodies
The Executive Leadership Team has responsibility for overseeing the quality assurance plan. It is supported by several committees that oversee our risk and audit quality outcomes – offering guidance, reviewing complex matters, and providing independent advice. Our committees and their responsibilities include the:
- Audit and Risk Management Committee – Provides oversight of risk, compliance, and governance. An independent committee advising the Auditor-General, it includes 3 external members with strong backgrounds in audit, governance, and risk. This year, in accordance with the tenure requirements of the committee’s terms of reference, we rotated 2 members off and welcomed 2 new members onto the committee.
- Quality Management Committee – Arbitrates any disputes regarding compliance with professional and ethical auditing requirements and reviews any proposed unsatisfactory quality assurance ratings. It supports QAO in achieving quality audit and assurance outcomes. It consists of the Deputy Auditor-General and the Assistant Auditor-General – Financial Audit.
- Technical Issues and Major Transactions Committee – Reviews complex accounting issues and major transactions. The committee oversees the consistency of approaches to accounting, auditing, and financial reporting matters, promoting audit quality. It includes the Auditor-General, Deputy Auditor-General, Assistant Auditor-General – Financial Audit, and the Head of Quality. Technical specialists and engagement leaders lead or contribute to discussion on agenda items.
- Modified Opinions Panel – Reviews proposed audit modifications and key audit matters for inclusion in independent auditor’s reports. It also considers material prior period errors and the remediation actions identified in the root cause analysis. It escalates matters to the Auditor-General for approval. It consists of the Deputy Auditor-General and the Assistant Auditor-General – Financial Audit. The Auditor-General and Head of Quality have standing invites to panel meetings.
Our annual report lists the names of external members and the frequency and attendance of committee meetings. The annual report is available on our website: www.qao.qld.gov.au/about-us/our-annual-report-transparency-report.
Leadership responsibilities for quality
Strong leadership is key to maintaining and improving audit quality. Clear roles and responsibilities ensure accountability and support a consistent approach across the organisation. Responsibilities for audit quality are shared across key roles, including:
- Executive Leadership Team (ELT) – Oversees the quality assurance framework and promotes integrity, independence, and professionalism, setting the tone and commitment to quality.
- Head of Quality – Implements enhancements to the quality management system and monitors compliance with policies and procedures. They lead the development and implementation of the quality assurance plan, and review and endorse all quality management outcomes.
- Engagement leaders – Senior directors and directors are our engagement leaders. They are appointed for their experience and skills, accountable for the quality of individual engagements, and regularly assessed against policies and performance frameworks.
- Engagement quality reviewers (EQRs) – Assigned to higher-risk audits and assurance engagements, they conduct reviews in accordance with Australian auditing standards. Our EQRs are current or former engagement leaders, or more senior staff with sufficient skills and experience. They are provided sufficient time to undertake this role. Two have experience in other jurisdictional audit offices.
- Audit service providers (ASPs) – Maintain quality frameworks that meet professional and QAO requirements. Their work is regularly reviewed and monitored for progress and emerging issues. They are responsible for the audit quality within their firms and their audit files.
Culture and values |
Our employee value proposition (EVP) links our strategic plan to our employee experience. The EVP incorporates ethical considerations through 5 components. Our EVP guides our decisions around people, culture, and capability. It influences how we attract talent, how we develop leaders, how we support career growth, and how we continue to improve our employees’ experience.
Queensland Audit Office.
By cultivating a positive culture, we ensure our people – both employees and contracted ASPs – are equipped to deliver high-quality outcomes for parliament and our clients.
Our culture is expressed by our 4 core values, which set our expectations for performance and behaviour. We regularly reflect on our culture and ensure our staff are living our values. The values are part of our performance discussions at the individual and team level.
| |
| |
| |
|
We regularly discuss our culture, including our expectations about audit quality, independence, objectivity, and professional scepticism, at our team and community meetings. The Auditor-General Auditing Standards and our policies establish our expectations and standards for audit quality and independence. Our expectations extend to our ASPs via our contractual arrangements which we communicate and monitor through our ASP forums, oversight of their service delivery, and quality reviews. Our training program includes ensuring that our staff undertake ethics training, in line with the requirements of Certified Practising Accountants Australia (CPA Australia) and Chartered Accountants Australia and New Zealand (CA ANZ).
Our independence and independence practices |
The Auditor-General is an officer of parliament, independent of government and not subject to direction or influence of others. They are appointed by the Queensland Governor in Council.
They are accountable to the parliament through the parliamentary Governance, Energy and Finance Committee. The committee has a monitoring and review function over the performance of the functions of the Auditor-General and the Queensland Audit Office.
Independence standards and practices
The Auditor-General Auditing Standards outline the independence standards that we apply. This includes those issued by the Australian Auditing and Assurance Standards Board, and the Accounting Professional and Ethical Standards Board. These standards apply to QAO staff, ASPs, and contractors.
The Auditor-General and Deputy Auditor-General are required to provide a declaration of interests to the Speaker of the Queensland Parliament. The Auditor-General is appointed for a fixed 7-year term, and they cannot work in the public sector for 2 years after their term expires.
Our policies and procedures help us communicate independence requirements, identify and manage threats, respond to breaches, and obtain annual written confirmation of compliance from all personnel required to meet ethical and legal independence standards.
All staff are required to demonstrate objectivity, integrity, and professional behaviour. The engagement leader is responsible for ensuring all staff involved in an audit engagement demonstrate independence of mind and appearance throughout the audit.
We monitor and consider all threats to independence when assigning QAO staff to audits. Annually, we require staff to identify close relationships within the public sector, and we use this information to determine the allocation of team members. The Deputy Auditor-General reviews and approves all declarations.
Rotation of key audit staff helps to provide a fresh perspective and reduces threats to independence, particularly familiarity threats. We maintain a database that tracks auditor involvement on engagements to facilitate succession planning and monitor compliance with our own rotation requirements.
Where an actual or potential conflict of interest is identified, the engagement leader must propose how QAO will manage the issue. The Head of Quality reviews and endorses the proposal to the Deputy Auditor-General for approval.
QAO maintains a register that records gifts or benefits received as part of official duties. This is published online to avoid any perception of conflicts of interest or inappropriate influence.
Independence and confidentiality requirements for our audit service providers
ASPs are contractually and legislatively required to protect the confidentiality of all information collected during an audit performed on our behalf. This means they cannot make or disclose protected information unless it is authorised under the Auditor-General Act 2009 (AG Act) or where it is required to perform official duties under the AG Act. This prevents them from using or disclosing information they obtain in our audits to third parties, including within their firms, except where required by law. Unauthorised disclosure is an offence and may attract significant penalties, such as a maximum imprisonment term of 12 months.
The independence and integrity of audit firms and their personnel are key considerations in selecting our ASPs. We review their independence before contracting them to undertake audits on our behalf and review their independence annually. We also do not allow our ASPs to provide non-assurance services to their QAO clients without prior written approval from the Auditor-General.
QAO takes confidentiality seriously and proactively reviewed the terms and conditions of our ASP engagements to ensure they were fit-for-purpose. We strengthened how we describe the confidentiality obligations in our contracts and reaffirmed our position through targeted communications with our ASPs. In July 2025, we introduced new requirements for:
- the lead partner to confirm they understand their confidentiality obligations within 10 days of signing the audit contract
- all team members who work on our audits, regardless of the extent of work, to sign an acknowledgement of their legal obligations to comply with the confidentiality requirements in the AG Act. These must be retained on the respective audit files
- the lead ASP partner on each audit to provide an overall independence declaration at the conclusion of each audit for the audit period.
Non-assurance services
Requests for non-assurance services | Our policy |
|---|---|
| Each year we receive a small number of requests from our ASPs to perform non assurance services for their QAO clients. We only approve those requests where the safeguards to maintain independence can be put in place to a satisfactory standard. | Our policy on ASPs providing non-assurance services to our clients is to:
|
Granting approval for ASPs to provide non-assurance services | Requests for non-assurance services during 2025–26 |
|---|---|
QAO does not engage ASPs to undertake financial audits of Queensland departments or integrity agencies, or conduct performance audits. Before granting approval for ASPs to provide non-assurance services, we consider:
|
Acceptance and continuance of client relationships and specific engagements |
We manage all engagements in accordance with a framework of policies, procedures, and guidance.
Financial audits
The Auditor-General Act 2009 mandates that the Auditor-General undertakes financial audits of all Queensland public sector entities, including local governments and controlled entities. We do not have the right to decline these clients or discontinue these client relationships. This is because these entities are created by state legislation. Parliament appoints the Auditor-General as the independent auditor to ensure there is transparency, accountability, and public reporting on the results of our audits.
We have developed approaches to maintain audit quality and manage our permanent relationship, including:
- assigning an engagement quality reviewer
- changing the engagement team, when required, to ensure a better match of skills and experience
- outsourcing the audit or aspects of the audit if specialist skills are required
- rotating staff to manage threats to undertaking a continuous audit
- revising the audit program to address particular risks in the audit.
Forward work plan
Our reports to parliament provide assurance, insights and advice, and recommendations for improvement that support the integrity of our system of government.
We focus on what matters to parliament and the public sector. The Auditor-General cannot be directed about the priority given to audit matters or the way in which audits are conducted.
We prepare a forward work plan that outlines the audits we plan to undertake over the next 3 years. We update the plan annually to ensure that we focus on the right topics and conduct them at the right time.
To ensure we select audit topics that matter most to Queensland, we apply a transparent and consultative process. Our forward work plan considers the strategic risks facing public sector entities and local governments. We identify the strategic risks by:
- scanning the environment in which public sector entities and local governments operate
- understanding the challenges in public sector administration
- consulting widely with stakeholders to identify and understand their concerns
- examining entities’ operations and performance
- analysing the results of our annual financial audits
- analysing the requests for audits we receive from members of the public, elected representatives, public sector employees, and other integrity offices.
Through our plan, we provide transparency to parliament on the work we intend to perform and why we consider it important. We also explain changes to our forward work plan to demonstrate independence in our decision-making.
Each year we receive requests from the public to undertake audits or review matters within our mandate that are not included in our forward work plan. We publish the requests we receive from local government councillors and members of parliament on our website. We also publish the Auditor-General’s response.
Engagement performance |
We expect our engagement teams to understand and meet their responsibilities for each audit, including the engagement leader’s role in managing and achieving quality. Our engagement leaders apply appropriate direction, supervision, and review based on the nature of the audit and experience of team members. This helps ensure work is performed to a consistent standard.
We have prepared audit methodologies to guide the work we undertake in financial audits, assurance reviews, and performance audits.
Our risk-based audit methodologies have been developed and maintained to ensure compliance with the Auditor-General Auditing Standards (which incorporate Australian auditing standards). They require us to develop an understanding of each client’s business and risks and apply this to the design and execution of our audits. We adapt our audit methodologies to developments in professional standards and to findings from quality reviews. Our quality reviews evaluate how well we have applied our methodologies.
| New sustainability assurance methodology developed | |
This year we launched our methodology for providing limited assurance reviews in accordance with ASSA 5000 General Requirements for Sustainability Assurance Engagements. We use this methodology when providing limited assurance for specific climate-related financial disclosures prepared in accordance with AASB S2 Climate-related disclosures. Nine large government companies were required to prepare these reports for the first time for 2025–26. We developed our methodology with assistance from the private sector and had it peer reviewed by another audit office to ensure it was fit-for-purpose for the public sector. | |
Delivering audits efficiently and effectively
We focus on delivering audits efficiently and effectively by applying consistent project management practices and monitoring progress throughout each engagement. Our audit teams use standardised tools, methodologies, and reporting templates to support quality and timeliness. We review key milestones and outcomes to ensure audits meet planned time frames and expectations.
We also engage with entities early to understand their operations and agree on audit timelines. This helps manage risks, avoid delays, and support effective communication.
Using data analytics to improve efficiency and effectiveness
We regularly assess our processes and look for ways to improve how we deliver our audits. This includes building analytical solutions for our audit teams that aim to improve their efficiency, effectiveness, or both. They are co-designed and built with subject matter experts (SMEs) from audit, methodology, data governance, information technology, and data analytics specialists.
A key design principle is to directly connect the solution to areas of the audit through training and direct references in our audit workpapers and templates. We assess the implementation of our new tools through targeted quality assurance reviews. The outcomes are shared with the engagement team via a targeted response, and thematically to all audit teams.
Determining our artificial intelligence journey
We use a consistent and evidence-based process to evaluate AI models and tools. Fundamental to this process is complying with the Auditor-General Act 2009 to not divulge, directly or indirectly, protected audit information. Accordingly, no client information is used to train AI models, and we do not allow QAO staff or our ASPs to upload protected audit information into AI tools. Our staff are required to undertake relevant training modules prior to using our endorsed AI models and tools.
We currently use AI to assist with understanding an entity and aspects of planning an audit engagement using publicly available information, and supporting corporate services staff in the efficient delivery of their work.
We will continue to review our audit methodology and data analytics tools, evaluating how AI is being integrated into the technology we use.
Audit service providers
The audit methodology and quality assurance systems our ASPs adopt for QAO-contracted audits must benchmark favourably with QAO’s methodology and system of quality management. We assess these when we register a new firm and as part of our regular firm reviews. As part of these reviews, we assess the firm’s policies and manuals to ensure they comply with the Australian auditing standards on quality management. We also review their internal compliance programs to ensure they are evaluating the operating effectiveness of their policies and procedures that guide their system of quality management.
Investigations
We may investigate matters that other integrity agencies, elected officials, and the community refer to us. We have policies and procedures to ensure consistency in undertaking these investigations. We have dedicated staff who address these requests and work with our audit teams to achieve efficiency. Our fact sheet on requests for audits explains how we undertake these investigations: www.qao.qld.gov.au/reports-resources/fact-sheets/requests-audits.
Our people and resources |
The core of our purpose is our contribution to public accountability, transparency, and the responsible use of public resources. Our staff derive a strong sense of purpose and professional pride from the knowledge that their work directly supports good governance and community outcomes.
To deliver high-quality audits, we must appoint and train people who can apply their experience, values, and professional judgement to support the conclusions in our audit reports.
We maintain a skilled workforce, able to deliver outstanding service and quality to our clients. To do this, we have developed a detailed understanding of the skills and capabilities that individuals require at certain points in their careers and a structured approach to learning and development.
QAO is a partner with CPA Australia in its Recognised Employer Program, and CA ANZ in its Approved Training Employer program. These programs recognise that QAO provides structured and supported learning opportunities for staff to complete their qualifications.
By fostering a culture of learning, we enable our people to build rewarding careers while ensuring the organisation remains responsive to the demands of the audit profession and the public sector.
Skill and competency expectations
Our policy requires that sufficient personnel with the technical competence necessary for the work are appointed to each engagement.
| Our updated competency framework | |
In 2025–26, we reviewed and re-designed our competency framework. This new framework:
The re-designed competency framework will be incorporated into our recruitment processes and our 2027 performance review process. All our learning and development offerings will also be mapped to the competency framework, making it easier to identify development opportunities aligned to roles and career aspirations. We support continuous learning and career development, as they are essential to maintaining a skilled and agile workforce. | |
Audit teams incorporate specialist skills based on the risks and complexity of the audit. The teams are led by an engagement leader, who is responsible for the delivery of our audits. Engagement leaders determine the necessary extent of direction, supervision, and review of junior staff in accordance with the Australian auditing standards, our policies, and guidance materials.
We encourage and support all financial, performance, and information systems auditors, and staff from other parts of our business, to complete postgraduate study. We offer them paid study time and financial assistance towards course fees and membership fees.
All financial audit managers and engagement leaders are required to have CPA or CA ANZ qualifications, or equivalent.
Our Senior Director who leads our information systems audit team is a qualified Certified Information Systems Auditor (CISA). Several other team members hold the Certified Information Systems Security Professional qualification (CISSP) or CISA, or are working towards their qualification.
We also encourage our engagement leaders and assistant auditors-general to complete the company directors’ course with the Australian Institute of Company Directors (or equivalent) to improve their understanding of the role of a board and how to interact with those charged with governance at our clients.
Financial audit engagement leaders hold qualifications, skills, and experience equivalent to the Australian Securities and Investments Commission’s (ASIC’s) requirements to be a registered company auditor. The ASPs we engage are registered company auditors.
Performance audit engagement leaders hold qualifications, skills, and experience across several different disciplines, fields, and sectors. It is this diversity that provides the skills and technical competency required to deliver our performance audit program.
Training our people
We assess our staff for technical competence, work experience, and training throughout their engagements. Their capabilities, competence, development, and performance evaluations are managed in accordance with QAO’s technical competency frameworks and policies.
We continue to develop more training that is delivered just-in-time and offers self-paced learning. This is reducing the volume of learning we ask staff to complete in our dedicated training periods and increasing the ability of staff to retain the knowledge and apply it to their work.
Our technical and non-technical courses:
- provide staff with the right skills at the right time to deliver quality outcomes for clients – and provide rewarding career experiences for our people
- keep staff at the forefront of new developments in the accounting, auditing, and regulatory environment
- embed quality and risk appetite within our culture and leadership.
On-the-job learning and staff training
We are committed to providing opportunities for technical training, leadership development, on-the-job coaching, and mobility arrangements (secondments within and external to QAO).
On-the-job training is a large part of ensuring auditors have the appropriate skills to undertake their work. We encourage teams to work together at our clients’ offices or co-locate at head office to share their experiences, collaborate, and teach.
We also give our staff the opportunity to gain further skills and experiences in other jurisdictional audit offices. We have annual exchange programs with the New Zealand Audit Office and the Office of the Auditor General British Columbia. Each year, staff travel to New Zealand and Canada for 4–6 weeks to develop skills and experience in relation to public sector auditing from a different perspective.
In return, each office sends staff to us for a similar length of time. They bring with them a wealth of knowledge and experiences that they share with the teams to which they are assigned and the broader staffing cohort.
In addition to on-the-job training and learning from others, staff are encouraged to complete targeted training to grow their skill set and address identified gaps.
| We provided an average of 66 hours of formal training and professional development per auditor. |
In 2025–26, we provided 8,627 hours of formal training and professional development to auditors, which averages to 66 hours per auditor on a full-time equivalent basis. This exceeds the expectations of the professional organisations of which staff are members.
Experience
We match the experience and skills of our engagement leaders to our clients’ industries and associated risks. We also aim to give staff new experiences to complement their existing skill sets and assist with succession planning.
We identify people with the right skills and experience to deliver our quality commitments. Our resourcing team forecasts our people requirements and ensures we have sufficient resources available. We also run targeted recruitment campaigns for staff with different levels of experience, supplemented by a continuous recruitment approach. This aims to recruit talented staff when they are available.
We monitor our audit and assurance staff profile, ensuring we have sufficient senior staff involved in audits, as illustrated in the staff headcount table below.
Profile of QAO audit staff | 26 June 2026 | 27 June 2025 |
|---|---|---|
| Executive Leadership Team | 5 | 4 |
| Engagement leaders | 21 | 20 |
| Engagement managers | 46 | 44 |
| Total number of senior staff | 72 | 68 |
| Percentage of senior staff to total audit staff | 38% | 38% |
Note: includes client service staff from financial audit, performance audit, and IS audit. Excludes staff on long-term leave and any vacancies for engagement leaders and engagement managers.
Using audit service providers to deliver audits
ASPs delivered 47 per cent of our audit opinions in 2025–26 (2024–25: 44 per cent). We engage ASPs to support the delivery of audits, leverage their regional knowledge, and access specialist resources.
QAO’s sourcing strategy sets principles for how audits are allocated between in-house teams and audit service providers. It aims to maintain QAO’s operational capacity, sector knowledge, and client relationships while balancing workload, budget, and continuity of auditors. Decisions consider audit duration, partner rotation, regional efficiencies, and the long-term use of providers where appropriate. We do not use our ASPs to undertake departmental audits, audits of integrity bodies, or performance audits. We may use subject matter experts to help us deliver audits, for example information technology experts in various aspects of cyber security.
Our ASPs are engaged under competitive tender processes. We assess the experience and skills of engagement partners and key team members and their suitability to conduct audits on our behalf.
We prequalify ASPs to confirm they have the required experience and qualifications, manage our risk to audit quality, and manage our obligations under independence and audit quality standards.
To be eligible to undertake audits on our behalf, we require ASPs to:
- be registered company auditors (RCA) with ASIC
- be a current member of CPA or CA ANZ
- be authorised to sign financial statements on behalf of their firm
- be part of a firm with at least one other RCA and a system of quality management that complies with ASQM 1
- be part of a firm that has recent public sector financial audit experience (within the last 2 years)
- have passed a criminal history check
- be part of a firm that complies with the Queensland Government supplier code of conduct and ethical supplier threshold policy.
A QAO senior director or director and a QAO manager work closely with each ASP to manage each audit. They review client correspondence, engage on significant risk matters, and oversee the delivery of the audit in accordance with the audit plan. The QAO staff also engage with the client to share sector-wide knowledge. The QAO senior director or director signs the independent audit report and is ultimately accountable for the quality of the audit in accordance with Australian auditing standard ASA 220 Quality Management for an Audit of a Financial Report and Other Historical Financial Information (ASA 220). The firm’s engagement leader is responsible for quality on the audit and must be able to demonstrate they have managed quality at an operational level in accordance with ASA 220.
At the conclusion of the audit year, we provide feedback from our clients to each of our ASPs about the audit process and engagement. We also provide them with our observations on their audit quality. We agree on an action plan with our ASPs to improve performance where it is needed and discuss how to continue doing the things that work well. As a group, we discuss the aggregate client survey feedback with all of our ASPs to help improve performance.
Information and communication |
Managing information
We have several established mechanisms to help us manage our information, including IT controls for in-house staff, and contractual controls for ASPs. Our staff also monitor current developments, media releases, and regulatory notices for risks occurring at our ASPs.
We responded to a media release by an ASP in May 2026 on its investigation of whistleblower allegations involving the inappropriate sharing of client documents within its audit division. QAO has obtained written assurance from the firm that the incident does not relate to QAO clients or operations. The firm has confirmed compliance with our obligations for protecting confidential information on the audits it conducts on our behalf.
Annual certification
We obtain annual certifications from all our ASPs, which include information on partners, systems, security, and legislative and contractual compliance, including mandatory reporting to QAO. This year we strengthened the certification to require greater detail on how our ASPs use artificial intelligence on our audits, and protect information obtained during the audits they perform on our behalf. This certification helps us:
- manage their independence
- ensure we are allocating an appropriate amount of work to ASPs
- understand changes in their system of quality management
- appropriately manage our contract with them, including compliance with mandatory data breach, confidentiality, and contractual obligations.
We take timely action to investigate a firm’s self-disclosure on compliance matters, or when we identify concerns from their certifications.
This year we undertook 2 follow-up enquiries to ensure that client data had not been indirectly disclosed to third parties. We concluded that while the ASPs had not met their contractual requirements to obtain Auditor-General approval prior to allowing these individuals to work on QAO engagements, there was no indication of a data breach and no audit information had been used inappropriately.
Communicating effectively within the Queensland Audit Office
We have established procedures and practices to identify, capture, process, maintain, and communicate information throughout QAO. These procedures are supported by IT applications that provide accurate, complete, and timely information that assists with decision-making in QAO’s system of quality management.
We share information across QAO through:
- industry groups – These communities of audit teams have similar clients or similar client objectives, enabling staff to share industry knowledge and experiences and solve problems together. Group members collaborate informally and in structured meetings, through which QAO also shares strategic messages
- cohort meetings – Graduates, junior auditors, engagement managers, and engagement leaders come together in cohort meetings. These meetings provide safe spaces for staff at the same level to share knowledge and experiences, receive coaching, tackle issues relevant to their role, and discuss how to implement strategic decisions
- quarterly all-staff seminars – These share information of strategic importance to QAO and provide a way for staff to ask questions of the ELT.
Audit teams use digital communication channels to informally share information and solve problems. This is an effective means of communication when our audit teams are travelling across Queensland. We also use digital communication channels to share information with our ASPs.
Digital records are maintained for all audit-related matters, using electronic audit software that allows engagement teams to share information with each other, the engagement quality reviewer, and those providing consultation.
We have one source of truth for documenting our audits. Auditors are required to transfer all audit evidence and analysis from working sites into the audit file as evidence that it is completed and reviewed. This step is required before the file is closed.
Communicating effectively with stakeholders
Engaging with our stakeholders, including parliament and state and local government entities, enables us to better align our business and audit practices with their needs and expectations. This helps drive long-term benefits for QAO and the public sector.
We recognise that effective communication between audit teams, client management teams, audit committees, and boards is critical to improving public services. Our communication covers the scope of audits, any threats to independence or objectivity, risk assessments, significant findings, and recommendations. Our reports are structured to communicate clear and concise messages and allow readers to quickly understand key findings.
We regularly report the progress of audits and our findings to those charged with governance, including chief executive officers, board chairs, and audit committees. We do this through meetings and through formal presentations of our plans, progress updates, and management letters explaining our findings.
Those charged with governance can provide a positive influence on the quality of an audit by demonstrating an active interest in the auditor's work and acting when they do not consider that appropriate quality has been provided.
We invite the chairs of audit committees to a twice-yearly briefing where we explain the strategic priorities of the office and discuss common findings from our audits.
We help parliament understand public sector entities’ financial management and performance to support its accountability role.
We report publicly to parliament on the results of all our audits and on the most significant audit issues we identify. Our reporting includes updating it on how entities are progressing with implementing our recommendations. This helps to highlight whether control weaknesses still exist or performance gaps are not fully resolved.
We also engage directly with ministers about recent and upcoming performance audits. This includes offering to meet with the ministers of entities being included in reports to parliament so they have an opportunity to discuss our findings and recommendations.
We proactively engage with parliamentary committees and secretariat staff to help us better understand committee needs in relation to our reports and other products. We hosted a parliamentary committee forum in March 2026 for committee members and secretariat staff.
The monitoring and remediation process
Our system of quality management identifies our quality objectives and assesses threats and risks to achieving them. It includes key controls and any additional controls being implemented to reduce risk to an acceptable level.
We have a senior manager dedicated to managing QAO’s risk process. They meet quarterly with our risk owners to ensure the risk register is complete, risks are accurately documented, and controls continue to operate effectively. The risk register includes strategic and operational risks.
The senior manager reports to the ELT quarterly and to each Audit and Risk Management Committee meeting on:
- changes in risk
- risk controls and additional treatments
- work to bring into appetite any risks outside our appetite or tolerance
- action being taken to address emerging risks or risks on a watchlist.
Where the risk falls outside our appetite or tolerance, the ELT discusses mitigating actions, including a remediation plan.
Separately, the Head of Quality provides a status update on the progress of the quality assurance plan to monthly ELT meetings and quarterly to Audit and Risk Management Committee meetings.
The Quality Management Committee meets as needed to review quality findings.
Improvement opportunities
We report improvement opportunities identified from quality assurance reviews to the ELT and Audit and Risk Management Committee at the completion of each review cycle.
We report more frequently on the root cause analysis for material policy breaches, material prior period errors in financial statements, and unsatisfactory quality assurance reviews. The reporting includes proposed remediation, issues identified during the root cause analysis, and responses to new and changing risks.
The themes of the open file review, engagement file review programs, and root cause analysis (where appropriate), together with improvement recommendations, are shared with all audit staff. Teams are required to acquit in their audit files how they have addressed the findings and recommendations.
Review team, milestones, and duration of the audit quality program
The Head of Quality is accountable for quality review, quality assurance, and active oversight of policies and procedures relating to quality assurance. They work closely with assistant auditors-general to share knowledge and provide advice on improvement opportunities arising from quality assurance activities.
The Deputy Auditor-General, as QAO’s Chief Operating Officer, is accountable for the effectiveness of training programs and delivering on QAO’s learning and development plan. The Head of Quality, Deputy Auditor-General, and assistant auditors-general collectively ensure the training program is appropriate.
We primarily use specialist contractors to deliver the quality review program. This helps us maintain independence of the review function. Internal senior managers and directors assist in reviewing our ASPs’ files and pre-certification reviews. These staff work across our technical team.
We develop an annual quality plan that establishes:
- files selected for open file reviews and engagement file reviews
- areas for deeper analysis
- the timing of quality reviews
- assignment of engagement quality reviewers
- reporting milestones.
Each internal engagement leader for financial audit is subject to one open and one engagement file review each year. However, financial audit engagement leaders with satisfactory ratings for each of their last 3 engagement file reviews, where at least 2 are rated as Satisfactory with no or minor findings, do not have an engagement file review in the following year.
Engagement file reviews are rated as either:
- Satisfactory with no or minor findings
- Satisfactory with findings that are more than minor but less than materially deficit. This means we raised some quality issues, but the engagement leader still had sufficient appropriate audit evidence to support their audit opinion
- Unsatisfactory. This means that there was a systemic lack of supervision and timely review by the engagement leader, and/or the engagement leader did not have sufficient appropriate audit evidence to support their audit opinion.
Our performance audit engagement leaders are subject to one engagement file review each year. Open file reviews are undertaken of performance audits where required. This may include situations where the engagement leader is newly appointed to the role.
We review our ASP engagement partners on a 3-year rotating basis. This approach reflects that our ASPs are also subject to quality reviews by their professional bodies, ASIC, and their in-house program. We request copies of all quality assurance reviews performed over our ASP engagement partners.
We aim to complete our reviews in time for teams to undertake recommended improvement actions in their current year audit files.
Remediation actions
Engagement leaders actively engage in the quality assurance process. They provide feedback and responses to questions we raise during the engagement file review process to ensure audit quality findings are fair and balanced. The engagement leader and quality assurance reviewer discuss appropriate remediation action. This may include performing further audit work or changes in practice going forward. A root cause analysis is undertaken for all unsatisfactory files and for issues formally raised with the engagement leader.
If an audit file is rated as unsatisfactory, we follow up with a targeted open file review prior to the subsequent independent auditor’s report being signed. This ensures that the deficiencies identified in the cold review have been appropriately addressed. Depending on the quality matter, we may require the engagement leader to obtain sufficient and appropriate audit evidence for the audit that was rated unsatisfactory. We will also schedule a further cold review over an audit by the same engagement leader to ensure that the audit quality issues are not systemic across their audits.
Monitoring audit quality across our audits
Monitoring audit quality is an important aspect of identifying emerging risks and opportunities, ensuring standards are being adhered to, and ensuring staff are performing well.
We monitor a range of audit quality indicators that span our culture and values, independence, recruitment, employee performance assessment, audit allocation process, quality assurance, timely reporting, and interaction with stakeholders. We monitor both quantitative and qualitative measures, which are reviewed annually for continuing relevance. The measures are listed in Appendix B.
The Head of Quality reports monthly to ELT on the outcomes of the quality assurance program, and 6-monthly on the root cause analysis and status of remediation actions.
Our Technical Issues and Major Transactions Committee and Modified Opinions Panel provide in-depth and expert analysis of complex financial accounting and audit issues, reporting of key audit matters, and proposed audit qualifications. These groups meet throughout the audit year as required.
Managing audit quality on our audits
Engagement leaders and engagement managers are provided with access to business intelligence dashboards that help them identify independence matters and risks to completing their audit in time and on budget.
Our audit approach requires us to plan, supervise, and manage our audits so the work performed provides reasonable assurance they comply with our policies and methodologies. The engagement leader is responsible for:
- the overall management of staff and the audit process
- engagement quality throughout the audit
- ensuring engagement quality reviewers are promptly briefed on significant matters.
Engagement leaders are required to lead client engagement and review all high-risk areas of their audits, significant judgements, and audit evidence that supports our audit findings. They also ensure the engagement manager or on-site team leader has performed a timely review of all other audit working papers.