For decades, Nepali audit firms lived by a simple rulebook: follow NSQC 1, tick the boxes, and move on. That era ends on 17 July 2026. The Institute of Chartered Accountants of Nepal (ICAN) has replaced the old quality control framework with two new standards — NSQM 1 and NSQM 2 — and every firm carrying out audits, reviews, or assurance engagements now has a hard deadline to become compliant. This guide walks through what changed, why it matters, and exactly what a small or mid-sized CA firm in Nepal needs to do before the deadline hits.
Why ICAN Introduced NSQM 1 and 2 — Quality Control vs Quality Management
The old NSQC 1 (Nepal Standard on Quality Control) treated quality as a static checklist: have a policy for independence, have a policy for training, have a policy for client acceptance. It worked reasonably well for large firms but often became a paperwork exercise for smaller practices that copied a template and filed it away.
NSQM 1 and NSQM 2, adapted from the global ISQM 1 and ISQM 2 standards, shift the entire philosophy from quality control to quality management. Instead of a fixed checklist, firms must now run a living, risk-based system: identify the specific quality risks your firm faces, design responses tailored to those risks, monitor whether the responses actually work, and adjust when they don't. A one-partner tax and audit practice in Biratnagar will have a very different risk profile — and therefore a different system — than a ten-partner firm auditing listed banks in Kathmandu. The standard expects that difference to show up in the actual design of the system, not just in the size of the file.
NSQM implementation timeline for Nepali CA firms
The Deadline: Mandatory From 17 July 2026
ICAN has set 17 July 2026 as the date from which NSQM 1 and NSQM 2 become mandatory for all applicable firms. This is not a "soft" recommendation with a grace period attached — it is the operative date for the firm's system of quality management to be up and running, evaluated, and capable of being reviewed. Firms that have spent 2024 and 2025 treating this as a distant compliance item now need to move from planning to execution, because the standard requires the system to have been operating — not just designed — before it can be properly evaluated for the first time.
In practice, this means firms should already have completed their risk assessment, documented their quality objectives, and assigned clear ownership within the partnership for who is accountable for the system as a whole. If your firm hasn't started, the priority now is a focused catch-up plan rather than a from-scratch multi-year rollout.
NSQM 1: The Firm-Level System of Quality Management
NSQM 1 applies to every firm that performs audits, reviews of financial statements, or other assurance and related services engagements — regardless of size. It requires the firm to design, implement, and operate a system built around eight interconnected components:
The firm's governance and leadership must demonstrate a genuine commitment to quality, starting at partner level. The firm must have a documented approach to relevant ethical requirements, including independence, that goes beyond a one-page declaration signed once a year. Client and engagement acceptance and continuance decisions must be risk-based, with clear criteria for when a client should be declined or an existing relationship ended. Engagement performance covers how work is actually carried out, reviewed, and documented across the firm. Resources — human, technological, and intellectual — must be adequate for the work the firm takes on, which is often the component smaller firms struggle with most given staffing constraints. Information and communication requires that quality-related information flows properly both within the firm and to external parties such as regulators. Finally, the firm must build a monitoring and remediation process that continuously checks whether the system is working and fixes it when it isn't.
Crucially, NSQM 1 requires an annual evaluation of the system by the individual with ultimate responsibility for quality (usually the managing partner), with a documented conclusion on whether the system is providing reasonable assurance that the firm's objectives are being met. This annual sign-off is new, and it creates personal accountability that didn't exist under NSQC 1.
NSQM 2: Engagement Quality Reviews — When Are They Mandatory?
While NSQM 1 governs the firm as a whole, NSQM 2 deals specifically with Engagement Quality Reviews (EQR) — an additional, independent check performed on certain engagements before the audit report is issued. NSQM 2 sets out the criteria firms must use to decide which engagements require an EQR, and it is mandatory for audits of listed entities and other engagements the firm's own risk assessment identifies as high-risk (for example, first-year audits of significant clients, engagements involving significant judgment, or clients facing financial distress).
The reviewer appointed under NSQM 2 must be independent of the engagement team and sufficiently senior and experienced to challenge the team's conclusions meaningfully. Their review focuses on the significant judgments made and the conclusions reached on the engagement — not a full re-performance of the audit, but a targeted, evidence-based challenge. The reviewer's work, and the fact that the review was completed satisfactorily, must be documented before the report is dated and released.
NSQM 1 (firm-level system) vs NSQM 2 (engagement quality review)
Related Revised Standards Bundled Into This Update
NSQM 1 and 2 didn't arrive alone. ICAN bundled several related standards into the same transition, and firms need to treat them as one connected package rather than separate projects:
NSA 220 (Revised) — Quality Management for an Audit of Financial Statements — realigns engagement-level quality responsibilities with the firm-level system under NSQM 1, making clear how the engagement partner's responsibilities connect to the firm's overall system. NSA 600 (Revised) — Special Considerations for Audits of Group Financial Statements — overhauls how group auditors plan and direct the work of component auditors, with much stronger documentation requirements around risk assessment at the group level. NSRS 4400 (Revised) covers agreed-upon procedures engagements and updates the reporting requirements for that class of work. Firms updating their audit methodology for NSQM should update their NSA 220, NSA 600, and NSRS 4400 templates at the same time, since these standards were designed as a coordinated set.
Current QA Review Scope — And What's Coming
As of today, ICAN's formal Quality Assurance (QA) review programme has focused primarily on firms auditing listed entities and a select group of other firms chosen for review each cycle. This has led some smaller practices to assume NSQM compliance is optional for them in practice, even if it is mandatory on paper.
That assumption is risky. ICAN has signalled that the QA review scope will widen over time as capacity allows, and firms that wait until they are selected for review to start building their system will be doing so under time pressure, with regulatory scrutiny already underway. Building the system now, while the review net is still relatively narrow, is the lower-risk path.
A Practical Readiness Checklist for Small and Mid-Sized CA Firms
For firms starting late or wanting to confirm they haven't missed a step, a practical sequence looks like this: assign one partner as formally accountable for quality management; run a documented risk assessment specific to your client base and service lines; write down your firm's quality objectives in plain language rather than copying a template verbatim; update engagement acceptance and continuance criteria to reflect a genuine risk-based decision process; confirm which engagements will require an EQR under your NSQM 2 criteria and identify who will perform those reviews; update your audit methodology and file templates to reflect NSA 220 (Revised) and NSA 600 (Revised) where relevant; and schedule the first annual evaluation of the system well before your busiest audit season, so any gaps can be fixed before real engagements are affected.
Where to Find ICAN's Implementation Support and Training
ICAN has been rolling out implementation guidance, workshops, and training notices for members ahead of the deadline. Firms should monitor ICAN's official notices and circulars directly, since implementation timelines, templates, and training schedules are updated periodically and are the most reliable source for firm-specific guidance. Engaging early with ICAN's continuing professional education sessions on NSQM is one of the most efficient ways for a small firm to build the system correctly the first time, rather than needing to rebuild it after a QA review finding.
For more on how the revised assurance standards connect to reporting requirements, see our related coverage of ICAN's quality assurance framework and recent NSA updates.
Discussion