Given the importance of the topic, it is necessary to clarify what is meant by quality in legal auditing. In fact, among professionals there is often little knowledge of the indications and obligations provided by the regulations and auditing principles.
The main sources are:
- Article 20 of Legislative Decree 27 January 2010, n. 39
- Article 26 of EU Regulation No. 537/2014
Italian law requires auditors to undergo audits by individuals selected by the Ministry of Economy and Finance (MEF), which maintains the Register of Statutory Auditors.
To date, the controls are not yet active, but the MEF has established a Consultative Committee (with Resolution no. 28368 of 17 February 2023, integrated by no. 80957 of 20 April 2023) to support the implementation of the system. The Committee has produced a final report with:
- Operational proposals for the start of checks
- Recommendations on the organization of inspections (team with at least one MEF inspector)
- Tips on adjusting your annual contribution to cover costs
Legislative Decree 25/2024 postponed the entry into force of the rules on the training of those responsible for quality controls (art. 2027 of Legislative Decree 5/39) to 2010, accelerating the implementation of the rest of the system.
Who is subject to quality controls?
Article 20 of Legislative Decree 39/2010 provides that all auditors who carry out assignments, except those at public interest entities (PIEs), are subject to controls.
The EIPs (pursuant to art. 16 of the same decree) are:
- Companies listed on EU regulated markets
- banks
- Insurance companies
- Reinsurance companies with headquarters in Italy or Italian branch office
For these entities, the control is regulated by art. 26 of the European Regulation. The selection of auditors to be subjected to controls will be done through risk analysis, taking into account the complexity of the assignments. For auditors of companies above the threshold (not small companies), the controls will be at least every six years.
Who carries out the checks?
The audits are carried out by registered auditors with at least 5 years of continuous experience:
- As task managers
- In auditing firms with management/supervision functions
- In public administrations that supervise the audit
They must also have specific training in quality control (art. 5-bis), meet the independence requirements and have no ties (direct or indirect) with the controlled entity. People with recent professional relationships, family ties up to the fourth degree, former partners or collaborators up to three years ago are excluded.
There is an obligation to maintain confidentiality regarding the information obtained during the inspection.
Subject of the checks
Quality control concerns:
- assessment of compliance with auditing principles
- compliance with applicable independence requirements;
- evaluation of the adequacy of the quantity and quality of the resources employed;
- assessment of the adequacy of audit fees;
- evaluation of the internal quality control system in the statutory audit firm.
Controls must be proportionate to the scope and complexity of the activity carried out.
Results of the checks
At the end of the audit, a report is drawn up with the outcome and any recommendations, also indicating the terms within which the auditor must comply. In the event of failure to comply, the MEF and Consob may apply sanctions within the limits of their respective competences.
The new international principles on quality
From 1 January 2025, the new international auditing principles, adopted with MEF resolution no. RR 184/2023, will come into force in Italy, which strengthen the approach to quality management:
ISA (Italy) 220 – Quality management at assignment level
The ISA Italia 220 principle regulates quality management at audit engagement level, attributing a key role to the responsible of the assignmentThe essential points of the principle are:
- Leadership and organizational culture focused on quality;
- Identifying and managing quality risks at the assignment level;
- Supervision and review of the work performed by the audit team;
- Monitoring the independence and suitability of team members.
The auditor is personally responsible for the quality of the assignment.
ISQM (Italy) 1 – Quality at study or company level
It replaces ISQC 1 and introduces a risk-based quality management system (QMS), according to which the audit firm or firm must:
- Design, implement and maintain a quality management system (SGQ) adequate and proportionate to the nature and complexity of the activity carried out;
- Identify and assess quality risks that may compromise the performance of assignments in accordance with standards;
- Develop specific responses to mitigate these risks;
- Continuously monitor the system and take corrective action where necessary.
The approach aims to create an internal culture of quality, involving governance and leadership.
ISQM (Italy) 2 – Review of assignment quality
Complementary to ISQM 1, it focuses on quality reviews of high-risk assignments, providing for:
- The designation of the Responsible for the review of the quality of the assignment;
- The timing and scope of the review, which must be completed prior to the issuance of the audit opinion;
- Documentation of the work carried out and the conclusions reached;
- The criteria of independence, competence and experience required of those who perform this function.
These principles improve the reliability of reviews, especially in complex contexts.
Conclusions
The activation of the quality control system is imminent. While waiting for full implementation, it is advisable for auditors to start structuring internal quality control models. This is not only a regulatory requirement, but also a strategic factor for reliability and competitiveness.
To facilitate this process, tools such as Legal Review GB They offer concrete support: guided paths, management of work papers, calculation of the risk matrix and planning of activities, represent a valuable help to operate in compliance and prevent critical issues in controls.
