Which assurance applies to which work
Most firms let four audit badges imply firm-wide oversight. Here is the actual position.
| Framework | What it covers | Applies to |
|---|---|---|
| ICAP Code of Ethics | Integrity, objectivity, professional competence and due care, confidentiality, professional behaviour | Every engagement we accept — audit, tax, accounting, corporate, advisory, technology, sustainability, Global Delivery |
| ISQM 1 — System of Quality Management | Governance, ethics, acceptance and continuance, engagement performance, resources, information and communication, monitoring and remediation | Audits, reviews, and other assurance and related services engagements |
| Quality Control Review (ICAP) | Independent inspection of completed engagement files and the quality management system | Audit practice |
| APRSP (ICAP) | Independent review of audit methodology and documentation | Audit practice — completed prior to QCR |
| Audit Oversight Board | Independent regulatory oversight outside the profession's own body | Audits of public interest companies |
| ISO 27001 · COBIT · NIST · SOC 2 | Information security, IT governance, controls assurance | Technology engagements and firm-wide data handling |
| Engagement-level controls | Acceptance, review, documentation, deadline control, defensibility | Every service line — set out in section V |
We would rather be precise about what our credentials cover than let four audit badges do work they were never designed to do.


