Upgrading Your Audit Quality Before It Becomes a Diligence Problem
How to move from a compliance audit to a credible audit — and why the difference matters the moment an external party looks at your books
Who this is for
SMEs whose statutory audit is currently performed by a small local CA firm, where the audit report is produced primarily for tax compliance rather than as a genuine assurance exercise. Businesses preparing for institutional investment, a bank facility renewal, or an IPO where audit quality will be scrutinised.
What it costs you to ignore it
The diagnosis behind it
This playbook is triggered by a Red or Critical finding on:
Vital 6 — Financial IntegrityThe Protocol
Assess your current auditor against four criteria: firm size and peer review status, sector experience, whether they issue a management letter alongside the audit report, and whether they have ever flagged a material issue. If the answer to the last two is no, the audit is a compliance exercise, not an assurance exercise.
If upgrading the auditor: shortlist two or three mid-tier CA firms with demonstrated experience in your sector and with clients of comparable size. Request credentials, a sample management letter, and references from two current clients.
Before appointing a new auditor, conduct a pre-audit review of your own books: identify any accounting treatments that will not survive scrutiny — revenue recognition timing, provisioning policy, capitalisation of expenses, and related-party disclosures. Resolve these before the auditor arrives.
Agree the audit scope with the new firm: confirm that the engagement includes a management letter, a going-concern assessment, and a review of internal controls. These are standard for a quality audit — if the firm does not offer them, find a different firm.
Act on the management letter. A management letter that is filed and ignored defeats the purpose of a quality audit. Assign each finding to an owner, set a resolution date, and report progress to the board.
What you can do yourself vs what needs help
Steps 1–2 and 4–5 are executable internally. Step 3 — the pre-audit review — should involve an independent CA who is not the incumbent auditor and has no interest in minimising the findings.