EQC Compliance Advisory · 1. Daily Regulatory Insights
Firm-Wide Competence and Engagement Controls
EQC video briefing · Core guide
HKSQM 1 in Practice: Competence, Capacity and Engagement Decisions
This video explains why staffing an engagement is more than a scheduling exercise under HKSQM 1. It shows how firms can evidence current competence, available capacity, appropriate supervision and engagement-level decisions. Viewers learn how training, assignments, consultations and monitoring should connect into a visible quality-management record.
(AFRC Inspection Findings & Quality Management)
FIRM-WIDE COMPETENCE GOVERNANCE GUIDE
The issue is not attendance; it is whether competence can be proved at the engagement decision
A firm can meet a professional-development administration deadline and still have a quality-management weakness. The real question is whether it can demonstrate, at the time it accepts, continues, staffs, reviews or signs an engagement, that the people assigned have the competence, authority, capacity and current technical understanding required for that specific work. Continuing professional development, CPA-registration renewal and fit-and-proper information are therefore not merely personnel records. They are evidence inputs to engagement-quality decisions.
That distinction is especially important for smaller and medium-sized practices. A spreadsheet showing completed hours does not explain whether a manager who attended a general IFRS session is equipped to supervise a judgment-heavy impairment, a regulated-entity assurance engagement, an IT-intensive audit or a group file involving component auditors. A practising certificate or CPA status does not by itself show that the individual has current industry experience, enough time, appropriate consultation support or independence from the review they are expected to perform.
The AFRC’s 2025–26 Oversight Report provides a timely prompt. Its recommendations are made to HKICPA concerning its specified functions; they do not create a new standalone legal obligation for every CPA firm. The report nevertheless identifies a practical control lesson for firms. AFRC found that 14% of sampled members remained non-compliant with CPD requirements in 2025, while nearly one in four CPAs renewed after the statutory deadline in the 2026 cycle. It also pointed to heavy reliance on self-declarations in fit-and-proper assessment and called for stronger practical support for applying standards.[1] [2]
EQC’s interpretation is straightforward: a firm that treats these signals only as an individual’s administrative issue misses a useful quality-management control. The firm should be able to connect its people records to its client-acceptance, engagement-assignment, consultation, review and monitoring decisions. This article explains how to build that connection without pretending that AFRC’s recommendations to HKICPA are direct new firm rules.
What AFRC actually reported—and what it did not
The August report assessed HKICPA’s performance of specified functions for the period from 1 April 2025 to 31 March 2026. Its scope included registration, CPD requirements, standard setting and training. It found progress in reducing the sampled CPD non-compliance rate from 32% in 2022 to 14% in 2025, but described the remaining level as persistently high. AFRC recommended a root-cause analysis and a targeted plan to bring the rate to 5% or below in the near term, ultimately to a negligible level.[1]
AFRC also observed that around 12,000 CPAs, or 24% of members, submitted renewal applications after the statutory deadline of 15 December 2025. More than 500 people removed from the register were reinstated in April 2026 after paying an administrative fee. The report recommended that HKICPA strengthen its renewal process, address repeated or unjustified late applications more firmly and deal with possible fit-and-proper concerns more promptly.[1]
Those are findings about the regulator’s oversight of HKICPA. They should not be converted into an unsupported statement that every firm must run AFRC-style background checks or that a late renewal automatically proves an engagement is defective. The firm-level lesson is narrower and more useful: if a person’s status, current learning, integrity concern or workload could affect an assignment, the firm should define an escalation route and retain the decision. This is ordinary governance evidence, not an invented new regulatory requirement.
The report’s fourth theme reinforces the point. AFRC noted that members need practical help to translate technical requirements into appropriate procedures and sound judgment. It recommended more systematic feedback from recurring deficiencies and emerging practice issues into local guidance, the Audit Practice Manual and eLearning.[1] A practice does not need to wait for the revised material to apply the same discipline internally: recurring review points should be turned into focused training, programme prompts, consultation triggers and file-review tests.
The four-link competence chain
A useful firm diagnostic is a four-link competence chain. The first link is professional status. The personnel record should show the individual’s role, relevant registration or practising status where applicable, renewal status, declarations and any restriction, condition or issue requiring escalation. The point is not to duplicate the external register. It is to ensure that the engagement partner or quality-management leader is not assigning responsibility on an unchecked assumption.
The second link is current capability. Record relevant learning by topic and outcome, not simply total hours. An engagement requiring revenue-contract judgment, going-concern work, audit-data analytics, regulated-entity reporting or cross-border group supervision calls for a different capability profile. The evidence can include structured learning, case-based technical briefing, supervised experience, consultation participation, review feedback and documented reading of a relevant standard or guide. A completion certificate alone is usually weak evidence of a person’s ability to apply the material.
The third link is assignment fit. At acceptance, continuance and team-planning stages, identify the significant risks and assign a named person who has the required knowledge and experience. Where no one fully meets the profile, the file should show the compensating response: specialist involvement, partner supervision, an engagement quality review, a technical consultation, reduced scope of responsibility or a decision not to accept the work. This shifts competence from a human-resources label to a risk-response decision.
The fourth link is learning feedback. Completed-file reviews, consultation logs, inspection findings and coaching notes should change the capability record. If reviewers repeatedly identify weak documentation of estimates, inconsistent fraud-response work or inadequate system walkthroughs, the firm has evidence of a practice-level need. The response should not be a generic annual reminder. It should specify the affected population, the technical topic, the expected file behaviour, the reviewer test and how the firm will know whether the learning was applied.
Start with the engagement, then work backwards to the person
The common but weak approach begins with a staff training calendar and asks whether everyone has attended something. A better approach begins with the engagement portfolio. List the engagements that contain elevated judgment, public-interest, sector, technology, group-audit, independence or regulatory features. Then identify the decisions that require particular competence and the people who will make, supervise or review them.
The AFRC’s 2025–26 inspection report is useful evidence for this approach. It asked firms to ensure that teams are adequately staffed with people who possess necessary skills and relevant industry experience, and it emphasised rigorous management of partner workloads for both engagement partners and engagement quality reviewers. It also identified revenue recognition, asset impairment, going concern, fraud, group-audit oversight and IT governance as continuing areas of challenge.[3]
A practical assignment memorandum can therefore contain five short fields: the material engagement risks; the required capability; the proposed preparer, manager, partner and reviewer; the evidence supporting their suitability; and the escalation or consultation route. It does not need to become a long biography. For an entity with significant cash-flow uncertainty, for example, the document might state that the manager has recent going-concern training and experience, the partner will review forecast challenge, and a technical consultation is required if covenant headroom is sensitive to untested management assumptions.
This record assists quality management because it makes resource decisions reviewable. A monitoring reviewer can ask whether the planned competence profile matched the actual file. If it did not, the firm can identify whether the problem was an inappropriate assignment, inadequate supervision, an unavailable specialist, an unrealistic fee, insufficient time or an ineffective training response. That is more informative than asking only whether the team had attended CPD.
Turn renewal and fit-and-proper information into an escalation gate
Annual CPA renewal is a statutory process. AFRC reported that late renewal was widespread and recommended a stronger approach at HKICPA level.[1] A firm should not substitute its own process for the external registration framework. It can, however, establish a simple internal gate: a person cannot be assigned as an engagement partner, engagement quality reviewer, signatory or otherwise designated role until the firm has checked the status information appropriate to that role and resolved any exception.
The gate should be proportionate. For most personnel, it may consist of an annual confirmation and a controlled record of the information checked. For senior people, quality reviewers or those working on higher-risk engagements, it may also capture relevant declarations, independence confirmations, regulatory restrictions known to the firm, bankruptcy or financial-propriety concerns where relevant, and decisions made after consultation. AFRC’s observation that fit-and-proper assessment relied heavily on self-declarations is a prompt to ask whether the firm’s own process is supported by independent information already legitimately available to it, rather than relying on an unsupported statement alone.[1]
The key control is not intrusive investigation. It is a defined exception protocol. If renewal evidence is incomplete, a declaration raises a concern, a restriction exists, or a partner’s status is uncertain, the assignment should be paused or escalated to the person responsible for quality management or firm leadership. The record should show the fact known, the decision-maker, advice obtained if needed, safeguards or restrictions imposed, and the date for reassessment. This avoids both extremes: casual acceptance of a red flag and blanket exclusion without a reasoned decision.
Use evidence of learning, not only evidence of attendance
AFRC noted that eLearning is increasingly important but that recorded seminars do not necessarily produce an effective self-paced learning experience. It recorded that embedded assessments had been introduced into selected core technical eLearning courses in March 2026 and that HKICPA plans further work on participation visibility and interactive features.[1] These are HKICPA implementation responses, not instructions to a firm. Yet they point to an effective internal test: did the learning change a decision, working paper or review behaviour?
For high-risk topics, the firm can require a short application record. It might ask the attendee to identify the affected client population, state one changed procedure or review question, and link that response to a revised audit programme, template, consultation note or completed-file review. For example, a session on impairment does not end with a certificate. The audit team should be able to demonstrate how it updated forecast-challenge procedures, sensitivity testing, discount-rate evidence, disclosure review or partner-review prompts on relevant files.
This is also where AP4.1 may be useful. AP4.1 generates audit programmes and engagement-level working papers while preserving client confidential data and avoiding upfront IT infrastructure investment. Within an approved firm methodology, that capability can help turn a documented learning need into a controlled programme prompt or work-paper amendment. The firm must still determine that the content is appropriate for the engagement, review the output, exercise professional judgment and retain responsibility for the audit conclusion.
Five questions for a quality-management reviewer
A monitoring or completed-file reviewer can test the competence chain without re-performing the whole engagement. First, was the engagement’s risk profile identified before key team assignments were finalised? The file should show why the matter was routine, specialist, high judgment or otherwise resource-sensitive.
Second, does the assignment record demonstrate relevant competence and capacity? Look for role-specific evidence, recent experience, training connected to the risk, workload considerations and a clear partner or reviewer role. Do not infer capability simply from seniority.
Third, was an exception identified and handled? If a skills gap, status uncertainty, time pressure, independence concern or unfamiliar industry arose, the reviewer should see a contemporaneous decision, consultation or safeguard rather than a retrospective explanation.
Fourth, did the actual file follow the planned response? A planned specialist review, consultation or enhanced partner challenge should leave visible evidence in the working papers. If it did not occur, the firm should record why and assess whether the conclusion remains supported.
Fifth, did the finding feed back into the system? The monitoring conclusion should distinguish a one-off performance issue from a recurring methodology, resourcing or training gap. The latter calls for a named remediation owner and a later effectiveness test. It is not enough to send a generic reminder and assume the root cause has been resolved.
Avoid three misleading shortcuts
The first shortcut is equating CPD completion with engagement competence. It is possible to complete hours without being ready to lead a complex engagement. The remedy is to connect learning to assignment and file evidence. The second shortcut is equating a current registration record with unrestricted suitability for every role. Registration remains important, but sector experience, workload, independence and consultation needs can still make an assignment inappropriate.
The third shortcut is treating every personnel exception as an individual disciplinary matter. A repeated pattern of late learning, thin specialist coverage, unplanned consultation or overloaded reviewers may indicate a firm-wide resource or culture problem. The AFRC inspection report explicitly links resource management, audit fees, professional scepticism, group oversight and technology capability to audit quality.[3] That makes personnel evidence a useful root-cause input, not merely an administrative compliance file.
What EQC can help with
EQC Compliance Advisory can assist through an External Annual SQM Monitoring Review and Completed File Monitoring Review. Within an agreed scope, EQC can evaluate whether a firm’s competence, assignment, consultation, supervision and remediation records connect properly to the risks shown on completed engagements. The review can distinguish the annual monitoring required by HKSQM 1 from rolling completed-file monitoring, and identify whether personnel and learning evidence supports the firm’s actual engagement decisions.
The work does not replace the firm’s responsibility for professional judgment, staff management, CPD compliance, registration, engagement acceptance, audit conclusions or regulatory reporting. It is designed to make one practical question easier to answer: can the firm show that the right people, with the right current capability and oversight, were assigned to the right work?
This article provides general information only. AFRC’s oversight recommendations are directed to HKICPA and should not be read as new direct legal obligations for every CPA firm. EQC’s competence-chain framework is practical guidance and does not replace a firm’s responsibilities for professional judgment, quality management, CPD compliance, registration, audit conclusions or regulatory reporting.
Continue your compliance learning
Watch other practical briefings in the EQC Video Library, or follow the latest regulatory developments and implementation insights.