Grab Offer
Skip to main content

Acenteus CCA Global Ltd

Audit Exemption Thresholds and ISQM 1 for Small UK Audit Firms

Table of Contents
Table of Contents

Last updated: 24 September 2026

This article is general guidance on UK company law and auditing standards and is not advice for a specific engagement. Thresholds, standards and FRC expectations change, so confirm the current position with legislation.gov.uk, the FRC and your recognised supervisory body before you act.

A UK company is exempt from audit if it qualifies as small, which since financial years beginning on or after 6 April 2025 means meeting two of three conditions: turnover of no more than £15m, a balance sheet total of no more than £7.5m, and no more than 50 employees. Those thresholds rose from £10.2m and £5.1m. The employee limit did not move.

For an audit firm that uprating is a fee event, not a technical one. Clients that were audited last year walk out of scope this year, and the firm still has to run a system of quality management under ISQM (UK) 1 across a smaller portfolio. This article covers both halves: the exemption rules as they now stand, and what ISQM 1 actually asks of a small firm, including the part most firms have thought least about, which is how the standard treats work done by somebody else.

Key takeaways

  • The thresholds: turnover £15m, balance sheet total £7.5m, 50 employees, for financial years beginning on or after 6 April 2025. Meet two of the three.
  • Two out of three, twice: a company must meet or fail the conditions in two consecutive financial years before its status changes, except in its first year.
  • Size is not the only test: public companies, banks, insurers, e-money issuers, MiFID firms and others are excluded whatever their size, and members holding 10% can demand an audit.
  • Groups have their own route: a UK subsidiary can take exemption under section 479A with a parent guarantee, but only if all five conditions are met and five documents are filed.
  • ISQM (UK) 1 replaced ISQC 1: effective for periods beginning on or after 15 December 2022, and it is a risk based system with eight components, not a set of policies.
  • Service providers are in scope: the resources component covers methodology providers, software and outsourced support. The firm stays responsible for the work either way.

What are the audit exemption thresholds in 2026?

Audit exemption follows small company status. Section 477 of the Companies Act 2006 states that a company qualifying as small in relation to a financial year is exempt from the audit requirements for that year, subject to sections 475, 476, 478 and 479, per legislation.gov.uk. So the audit question is really a size question.

The size thresholds were uprated for financial years beginning on or after 6 April 2025, as ICAEW sets out. The employee limits did not change at any tier, which is the detail most summaries skip.

Measure Micro before Micro now Small before Small now Medium before Medium now
Turnover, not more than £632k £1m £10.2m £15m £36m £54m
Balance sheet total, not more than £316k £500k £5.1m £7.5m £18m £27m
Average employees, not more than 10 10 50 50 250 250

Balance sheet total means total assets, not net assets, which is the single most common error we see on a borderline file. ICAEW’s determining the size of a company guidance is the reference worth keeping open when a client sits near the line.

How does the two out of three test work?

A company qualifies as small if it meets at least two of the three conditions. It does not have to meet all three, and the two it meets can be different from one year to the next. A company with £16m turnover, a £6m balance sheet total and 40 employees is small, because it satisfies two of the three despite breaching the turnover limit.

The two consecutive year rule

After a company’s first financial year, a change in whether it meets the conditions only affects its status if that change happens in two consecutive financial years, per ICAEW’s helpsheet on whether a company or group is small. That cuts both ways. A company that grows past the thresholds stays small for one more year. A company that shrinks below them stays large for one more year.

The practical consequence for an audit firm is that the uprating did not empty the portfolio in one go. Companies that were medium-sized on the old thresholds and small on the new ones still needed a second qualifying year before the exemption bit. For most December year ends that second year is the one being planned now.

The first financial year is different

In its first financial year a company only has to meet two of the three conditions in that year. There is no consecutive year test, because there is no prior year to compare against. Newly incorporated subsidiaries of large groups catch people out here, because the company can be small on its own numbers while the group is not, and group status overrides it.

How does group and subsidiary audit exemption work?

A company in a group has to clear two hurdles: it must be small itself, and the group must qualify as small. If the group is an ineligible group, no member of it can take the small companies exemption regardless of its own size. That is why a two person UK subsidiary of a listed parent still gets audited.

The section 479A route and the parent guarantee

Where the group test fails, a UK subsidiary can still take exemption under section 479A if its parent is established under the law of any part of the United Kingdom and all five conditions are met, per legislation.gov.uk. This is the route most people mean when they say parent guarantee, and it is conditional in a way that catches firms out at filing.

Condition What it requires
Members' agreement All members of the company must agree to the exemption for the financial year in question
Parent guarantee The parent undertaking must give a guarantee under section 479C for that year
Consolidation The company must be included in consolidated accounts drawn up by the parent for that year or to an earlier date in it
Disclosure The parent must disclose in the notes to the consolidated accounts that the company is exempt by virtue of section 479A
Filing The directors must deliver five documents to the registrar on or before the date they file the accounts

The five documents are the written notice of the members’ agreement, the section 479C statement of guarantee, a copy of the consolidated accounts, a copy of the auditor’s report on those accounts, and a copy of the parent’s consolidated annual report. Miss one and the exemption is not available, which means the accounts filed without an audit report are wrong.

My view: section 479A is more expensive than it looks. The parent is guaranteeing all the subsidiary’s liabilities outstanding at the year end. Finance directors sign it because the audit fee is visible and the guarantee is not, and it is worth making sure somebody in the group has actually read section 479C before the form goes in.

Who cannot claim audit exemption, whatever their size?

Size does not save a company that is excluded by its nature. Section 478 of the Companies Act 2006 puts three categories outside the small companies exemption entirely, per legislation.gov.uk.

  • Public companies: any public company, regardless of turnover, balance sheet total or employee numbers.
  • Regulated entities: authorised insurance companies, banking companies, e-money issuers, MiFID investment firms, UCITS management companies, companies carrying on insurance market activity, and the scheme funder of a Master Trust pension scheme.
  • Certain representative bodies: special register bodies under trade union law, employers’ associations, and the Northern Ireland equivalents.

There is a fourth route into an audit that has nothing to do with size or sector. Under section 476, members representing not less than 10% in nominal value of the issued share capital, or 10% in number of the members where there is no share capital, can give notice requiring an audit, per legislation.gov.uk. The notice must be given not later than one month before the end of the year it relates to.

That one month deadline matters more than it used to. A minority shareholder who was relying on a statutory audit that has now disappeared under the uprated thresholds has a right, but only if they use it in time. Worth a line in the letter to any client with a minority holding on the register.

What is ISQM (UK) 1, and what did it replace?

ISQM (UK) 1 is the FRC’s quality management standard for firms performing audits or reviews of financial statements, or other assurance or related services engagements. It replaced ISQC (UK) 1 and is effective for audits of financial statements for periods beginning on or after 15 December 2022, per the FRC and ICAEW’s overview of the standards.

The change is not cosmetic. ISQC 1 asked for policies and procedures. ISQM 1 asks the firm to set quality objectives, identify and assess the quality risks specific to its own circumstances and engagements, then design and implement responses to those risks. It is a risk assessment, run annually, about the firm rather than about a client.

It arrives with two companions. ISQM (UK) 2 covers engagement quality reviews, which were previously engagement quality control reviews under ISQC 1, and ISA (UK) 220 (Revised) covers quality management at the engagement level, including a new stand back requirement for the engagement partner to determine they have taken overall responsibility for quality on the audit.

The eight components of a system of quality management

A system of quality management under ISQM 1 addresses eight components. Every quality risk a firm identifies has to sit under one of them, and the annual evaluation reports against all eight.

# Component What a small firm is actually being asked
1 The firm's risk assessment process How do you identify quality risks, and how do you know the process caught them?
2 Governance and leadership Who holds ultimate responsibility for the system, and who is accountable for operational responsibility?
3 Relevant ethical requirements How do independence breaches get identified, reported and resolved, including across a small partner group?
4 Acceptance and continuance What makes you turn work down, and is that judgement evidenced rather than assumed?
5 Engagement performance Direction, supervision, review, consultation, differences of opinion and engagement quality reviews
6 Resources People, technology and intellectual resources, including software, methodology and external service providers
7 Information and communication How quality information flows up, down and out, including to those charged with governance
8 Monitoring and remediation Ongoing and periodic monitoring, root cause analysis of deficiencies, and evidenced remediation

ICAEW’s quality management hub carries working material on the harder components, particularly the risk assessment and root cause analysis. The component small firms underestimate is not the risk assessment. It is monitoring and remediation, because it requires you to find your own deficiencies, work out why they happened, fix the cause rather than the file, and evidence that you did.

What does the annual evaluation require from a small firm?

ISQM (UK) 1 requires the individual assigned ultimate responsibility and accountability for the system to evaluate it at least annually, as at a point in time, and to conclude whether it provides reasonable assurance that the objectives of the system are being achieved. The conclusion is one of three: the system does provide that assurance, it does so except for identified deficiencies, or it does not.

The FRC’s expectation, set out in its guidance to firms designing and implementing the standards, is that firms had established their quality objectives, identified and assessed their quality risks, designed and implemented responses, and designed and implemented monitoring and remediation activities by the effective date, as reported by ICAEW. Retrofitting quality risks to existing ISQC 1 policies does not meet the requirement.

  • Scalability is real, but it is not a discount: a sole practitioner with four audits runs a genuinely smaller system than a 40 partner firm. The components do not reduce, the responses do.
  • Documentation is the deliverable: an undocumented judgement is indistinguishable from no judgement at an inspection visit, and root cause analysis in somebody’s head does not evidence remediation.
  • The evaluation is a point in time: it is a conclusion as at a date, supported by monitoring performed across the year, not a task done in the last week of the year.
  • One person owns it: ultimate responsibility sits with a named individual. In a small firm that is usually the senior partner, and it cannot be delegated away.

How does ISQM 1 treat outsourced audit support and service providers?

Service providers sit inside the resources component, and ISQM 1 makes specific reference to them. That covers the obvious ones, methodology publishers and audit software vendors, and it equally covers a firm that prepares working papers for you. If a resource obtained from outside the firm is used in performing engagements, it falls to be considered in the system of quality management.

The point that matters commercially: outsourcing work does not outsource responsibility. The engagement partner still takes overall responsibility under ISA (UK) 220 (Revised), the firm still owns the quality risk, and the evidence that the provider is appropriate has to exist in the firm’s own documentation. A provider who tells you their work removes a risk from your system has misread the standard.

  • Assess before you appoint: competence, capabilities, independence, and whether the provider’s own quality processes are appropriate for the work you are giving them.
  • Document the assessment: what you looked at, what you concluded, and when. Our outsourced accounting quality control checklist covers the evidence trail.
  • Keep the review inside the firm: the provider prepares, your team reviews and signs. That split is not a preference, it is what the standards require.
  • Data protection is part of it: audit files carry personal data, so the provider’s security and UK GDPR position is a live quality and legal question. Our guide to security and GDPR red flags sets out the warning signs.
  • Monitor it like any other response: a provider is a response to a quality risk, so it falls within monitoring, and a deficiency in their work is a deficiency in your system.

On what can and cannot move, we have written the detailed version separately. Our guide to audit outsourcing working papers breaks the file down into what is fully outsourceable, what needs oversight, and what cannot leave the firm because it carries statutory responsibility, and our piece on improving audit efficiency with outsourced support covers what that does to turnaround.

What the threshold change and ISQM 1 do to a small firm together

They pull in opposite directions, and that is the honest thing to say about this year. The uprating removes audits from the portfolio. ISQM 1 raises the fixed cost of being registered to do the ones that remain. A firm with 30 audits that loses eight of them carries essentially the same system of quality management across 22.

  • The arithmetic: the SoQM, monitoring, root cause analysis and the annual evaluation are largely fixed cost. Spread over fewer engagements, the cost per audit rises.
  • The strategic question: whether audit remains a service the firm offers at all, or whether registration is being carried for a handful of engagements.
  • The third option: keep the registration and the client relationships, and move the volume work. That is the case we set out in the strategic advantages of audit outsourcing and, at practice level, in scaling practice capacity.
  • What does not work: cutting monitoring to protect margin. It is the component the FRC and the recognised supervisory bodies look at first, and it is the one that fails an inspection.

For firms weighing that up for the first time, our decision framework for first time outsourcing works through the sequencing, and building practice capacity without permanent hires covers the staffing side of the same question.

How Acenteus Accounting helps

We prepare audit working papers for UK registered firms and hand them back for review and sign off. The split never moves: our team prepares and reconciles, your team reviews, and your engagement partner takes responsibility. Nothing goes to a client or a file as finished without your name on it. That is our audit outsourcing service.

Because we are a resource inside your system of quality management, we expect to be assessed and documented rather than taken on trust. Ask for the competence evidence, the independence position, the data protection terms and the monitoring arrangements, and put them in your file. How the engagement is run, from file handover to review turnaround, is on our outsourcing for UK accounting firms page, and the onshore against offshore trade offs are in offshore versus onshore accounting.

You can check how that works in practice rather than taking it from a service page. We hold a verified Clutch profile with a 5.0 rating across three client reviews. Shobhana Solanki, Managing Director of TAXTEK CAMBRIDGE LTD in Cambridge, wrote that our “openness to questions and feedback fostered a positive working relationship, which helps to build trust”. A director at a financial services company in Northern Ireland wrote that we “provide high-quality work at a cost-effective rate”.

The same review set notes that clients would like even more proactive suggestions, and that is fair. On audit work it matters more than on most, because the value of a provider is partly in flagging the thing nobody asked about. The communication rhythm that makes that happen is the subject of our client communication framework for offshore accounting.

If you want to work out what the threshold change has done to your own audit portfolio, send us the client list with year ends and the three size measures and we will tell you how many fall out and when.

Frequently Asked Questions (FAQ)

A company is exempt from audit if it qualifies as small, meaning it meets two of three conditions: turnover of no more than £15m, a balance sheet total of no more than £7.5m, and no more than 50 employees. These apply to financial years beginning on or after 6 April 2025.

The company size thresholds were uprated for financial years beginning on or after 6 April 2025. Small company turnover rose from £10.2m to £15m and the balance sheet total from £5.1m to £7.5m. The 50 employee limit was unchanged.

Balance sheet total means total assets, that is the total of fixed and current assets, before deducting liabilities. It is not net assets, which is the most common error on a borderline company.

A company qualifies as small if it meets at least two of the three size conditions, not all three. The two it satisfies can differ from year to year, so a company can breach the turnover limit and still be small.

Yes, under section 479A, if the parent is established under the law of any part of the UK, all members agree, the parent gives a section 479C guarantee, the company is in the consolidated accounts, the parent discloses the exemption, and five documents are filed with the registrar.

Public companies, authorised insurance companies, banking companies, e-money issuers, MiFID investment firms, UCITS management companies, companies carrying on insurance market activity, Master Trust scheme funders, and certain trade union and employers' bodies.

Yes. Members holding not less than 10% in nominal value of the issued share capital, or 10% in number of members where there is no share capital, can require an audit by giving notice not later than one month before the end of the financial year concerned.

ISQM (UK) 1 is the FRC quality management standard for firms performing audits, reviews and other assurance or related services engagements. It replaced ISQC (UK) 1 and applies to audits of financial statements for periods beginning on or after 15 December 2022.

For audits of financial statements for periods beginning on or after 15 December 2022. Firms were expected to have designed and implemented their system of quality management, including monitoring and remediation activities, by that date.

Eight: the firm's risk assessment process, governance and leadership, relevant ethical requirements, acceptance and continuance, engagement performance, resources, information and communication, and monitoring and remediation.

ISQM (UK) 2 deals with engagement quality reviews, covering the appointment and eligibility of the reviewer and their responsibilities for performing and documenting the review. It replaced the engagement quality control review requirements in ISQC 1 and the earlier ISA 220.

Related Posts

Discover Our Support Options


Discover Our Support Options


End-to-End Financial Management


Scalable Accounting Support