Every feature of SQMTrove shown in this manual, in alphabetical order, with the area of SQMTrove in brackets and the steps (chapter.step) that show it.
| Feature | Where in this manual |
|---|---|
| 18 audit quality indicators year on year (print) (Reports) | 16.1 The quality indicators; 16.2 More indicators |
| Acceptance and continuance decisions (independent approval of high risk, legal obligation, predecessor, decline) (Acceptance) | 8.3 An acceptance decision for a new client; 8.4 Decide, with independent approval of high risk; 8.5 The decisions register |
| Add a person (role and its description, temporary password shown once, invitation for an existing login) (Users) | 3.1 Add a person; 3.2 Give the temporary password privately |
| AI assistance tab (Settings) | 19.1 AI assistance is off; 19.2 Provider, model and key; 19.3 Limits, minimisation and acknowledgement |
| Ask ISQM with citations (AI assistance) | 19.4 Ask ISQM |
| Audit trail: filters, entry detail (before / after), verify integrity (Audit trail) | 21.1 The audit trail; 21.2 An entry in full |
| AuditTrove link tab (Settings) | 18.1 The link is off; 18.3 Linked; 18.4 The archived file arrives |
| AuditTrove reads the published policies and restricted entity list (AuditTrove link) | 7.7 The restricted entity list |
| Automatic findings: report before EQR, late assembly, open differences or consultations (Engagements) | 9.11 A report dated before the review; 13.1 The findings to evaluate |
| Breaches (each also a monitoring finding) (Ethics) | 7.10 Record a breach; 7.11 Communicate and close the breach; 7.12 The breaches register |
| Capacity of partners and reviewers (Resources) | 6.6 Capacity of partners and reviewers |
| Change password (Settings) | 2.5 Change your password |
| Change role, switch access off, remove from the firm (Users) | 3.7 Change a person's role or access; 3.8 Remove a person from the firm |
| Clients register (entity type, PIE category, publicly traded, law requires EQR, risk, audit client, TIN, first year) (Acceptance) | 8.1 The client register; 8.2 A client's public interest status; 8.6 The client register after the decisions |
| Close a deficiency (only when actions are effective) (Monitoring) | 13.12 Close a deficiency; 13.13 The deficiencies register |
| Code at every sign-in; recovery-code option; auto-submit on six digits (Access) | 1.7 Enter the code from your app |
| Communication of a deficiency to leadership (Monitoring) | 13.9 Actions and communication |
| Communications log (Information) | 10.6 The communications log |
| Competence and accreditations (Resources) | 6.5 Competence and accreditations |
| Complaints and allegations register: investigation, outcome, closing (confidential) (Complaints) | 14.3 The complaints register; 14.4 Investigate and conclude |
| Complete a declaration with exceptions (Ethics) | 7.2 Complete a declaration |
| Component conclusions; overall ISQM 1.54 conclusion limited by open deficiencies; basis; ISQM 1.55 actions and communications (Evaluation) | 15.4 Conclude on each component; 15.5 The overall conclusion; 15.6 Actions and communications |
| Components cards and heat map (click-through to risks) (Dashboard) | 1.14 Components and the heat map |
| Conditions, events and changes (ISQM 1.25(a), 27) (Risk assessment) | 5.15 Record a condition, event or change; 5.16 The conditions register |
| Consultations (Engagements) | 9.13 Record a consultation; 9.14 The consultations register |
| CPD records (self-service) and compliance by rule and year (Resources) | 6.3 Record your own CPD; 6.4 CPD compliance |
| Create a deficiency from a finding; link further findings (Monitoring) | 13.3 Make a deficiency from a finding; 13.4 The deficiency and its findings |
| Creating a firm inside SQMTrove is closed for TroveUniverse subscribers (Settings) | 22.2 Accept or decline |
| Custom roles (cannot exceed your own access); delete a role (Users) | 3.6 Create a custom role |
| Declaration recorded on behalf of a person without a login (Ethics) | 7.5 Record a declaration on someone's behalf |
| Deficiency: severity and pervasiveness factors, risks and responses affected (Monitoring) | 13.5 Evaluate severity and pervasiveness |
| Differences of opinion (Engagements) | 9.15 Resolve a difference of opinion |
| Drafts: quality risks for an objective, root cause analysis, remedial actions, evaluation basis, policy summary and section, transparency narrative (AI assistance) | 19.5 Draft risks for an objective; 19.6 Draft a root cause analysis |
| Due for review (technology, providers, practising certificates, accreditations, methodology) (Resources) | 6.12 Due for review |
| Engagement inspection checklist, raise findings for 'No', grade and complete, working papers (Monitoring) | 11.5 Inspect an engagement file; 11.6 Grade and complete the inspection |
| Engagement register (exceptions column, EQR link, CSV export) (Engagements) | 9.3 Add an engagement; 9.4 The engagement register; 16.6 Export a register to a spreadsheet |
| EQR checklist (ISQM 2.25), save, complete, reopen (Engagements) | 9.7 Perform and record the review; 9.8 Confirm completion; 9.9 The completed review |
| EQR page: determination, eligibility and candidates, appoint (Engagements) | 9.5 Check eligibility and appoint the reviewer; 9.6 The reviewer is appointed |
| Evidence files on any record; new versions and version history; remove (Evidence) | 9.11 A report dated before the review; 12.2 Record the report; 12.5 Keep versions of a file |
| Evidence pack as at the date (live, then frozen at signing) (Evaluation) | 15.3 The evidence |
| External inspections and their findings (Monitoring) | 12.1 Record an inspection visit; 12.2 Record the report; 12.3 Add each finding; 12.4 The inspections register |
| Fees and dependency (15% / 30%, Nigerian 80% cap), client fees, firm total fees (Ethics) | 7.16 Fees and fee dependency |
| Findings: sources, evaluation (deficiency / not), engagement follow-up (ISQM 1.45) (Monitoring) | 13.1 The findings to evaluate; 13.2 Evaluate a finding |
| Firm details (name, legal name, address, city, country, email, phone, network) (Settings) | 2.1 Record the firm's details |
| Firm policy: offline on/off, maximum age (Offline) | 20.1 The firm's offline policy |
| Firm tiles (objectives, risks, responses, gaps, monitoring, findings, deficiencies, actions, independence, partner cycle, last evaluation) (Dashboard) | 1.13 The dashboard: what needs you, and how the system stands |
| Firms: several firms per login, invitations (accept / decline), open a firm (Settings) | 22.2 Accept or decline; 22.3 Switch between firms |
| First dashboard with the guided set-up banner; the menu by role (Dashboard) | 1.4 The first dashboard and the menu |
| For you: declarations, policies to read, tasks, remedial actions, activities, EQRs, investigations (Dashboard) | 1.13 The dashboard: what needs you, and how the system stands; 1.16 What staff see |
| Forgotten password: request, email with one-time link, new password, done (Access) | 1.8 Forgotten your password? Ask for a link; 1.9 Check your email; 1.10 Open the reset email; 1.11 Choose a new password; 1.12 Sign in with the new password |
| Gaps list (Risk assessment) | 5.14 The gap list |
| Gifts and hospitality (self-service, approval) (Ethics) | 7.8 Record a gift; 7.9 The gifts register |
| Guided set-up: questions, starter library preview, add library risks and responses (Risk assessment) | 5.1 Answer the set-up questions; 5.2 Read the library before you add it |
| High-risk threshold, EQR policy (other PIEs, high-risk clients, fee threshold), Nigerian rules (Settings) | 2.3 High-risk threshold, engagement quality reviews and the Nigerian rules |
| Import engagements from a spreadsheet (CSV) (Engagements) | 9.1 Import engagements from a spreadsheet; 9.2 Check the import result |
| Import: engagement register, acceptance decisions, breaches, findings, AuditTrove indicators, received events (AuditTrove link) | 18.4 The archived file arrives; 18.5 The engagement in the register |
| Independence and fit-and-proper campaigns (open, close, reopen) (Ethics) | 7.1 Open the annual campaign; 7.3 The campaign as the ethics partner sees it |
| Information after acceptance (ISQM 1.34(d)(i)) (Acceptance) | 8.7 Information after acceptance; 8.8 The information-after-acceptance register |
| Inspection pack (print / save as PDF) (Reports) | 16.3 The inspection pack; 16.4 Monitoring and remediation in the pack; 16.5 The evaluation in the pack |
| Inspector (read-only) role for a regulator's inspection (Users) | 3.13 Give a regulator read-only access; 3.14 What an inspector sees |
| Key audit partner rotation, firm tenure, service history (Ethics) | 7.17 Rotation and firm tenure |
| Leadership performance evaluations (not by themselves) (Governance) | 4.4 Evaluate a leader's performance; 4.5 The leadership evaluations |
| Make available offline (device warning), the copy, refresh, remove (Offline) | 20.2 Make a copy on this device; 20.3 Confirm the device is protected; 20.4 The copy on this device |
| Methodology and templates (intellectual resources) (Resources) | 6.10 Methodology and templates |
| Monitoring activities (types, inspector objectivity check) (Monitoring) | 11.2 Add a monitoring activity; 11.3 The activities of the year |
| Monitoring overview (Monitoring) | 11.7 The monitoring overview |
| Monitoring plan with the ISQM 1.37 considerations, approval (Monitoring) | 11.1 Approve the monitoring plan |
| Most important gaps; regulatory deadlines (60 days) (Dashboard) | 1.15 Gaps and regulatory deadlines |
| My profile (name, professional number, qualifications) (Settings) | 2.4 Your own profile |
| My tasks; recurring tasks schedule the next one; evidence (Tasks) | 17.1 My tasks; 17.2 Complete a task with evidence; 17.3 The next task is scheduled |
| Network content: export framework (JSON), import network framework (prefix, lock) (Risk assessment) | 5.18 Versions, and network content |
| Nine built-in roles and the module × level permission matrix (Users) | 3.4 Roles and permissions; 3.5 Partner, manager, staff and inspector roles |
| Non-assurance services with the IESBA PIE prohibitions (Ethics) | 7.14 A prohibited non-assurance service; 7.15 Non-assurance services |
| Notifications page: unread, mark read, mark all as read, email copies (Notifications) | 1.17 Notifications |
| Objectives: the required objectives (locked), additional firm objectives (Risk assessment) | 5.8 Quality objectives; 5.9 Add a firm objective |
| Only an owner or administrator assigns ultimate responsibility (Governance) | 4.2 Assign ultimate responsibility |
| Other roles: EQR appointer, ethics, technical, complaints (Governance) | 4.3 Check what is still to resolve |
| Overview: counts and inherent / residual heat maps (Risk assessment) | 5.6 The overview and heat maps |
| Partner dashboard sign-on (member mode: existing members only) (TroveUniverse) | 22.4 Open a firm from the partner dashboard; 22.5 The sign-on in the audit trail |
| Partner inspection cycle (Monitoring) | 11.4 The partner inspection cycle |
| People list: role, access, two-factor status, last sign-in (Users) | 3.3 The people list |
| People register (grade, office, EP, EQR eligibility, body, FRC no., practising expiry, CPD rule, independence, joiners and leavers) (Resources) | 6.1 The people register; 6.2 A person's professional details |
| Performance appraisals (Resources) | 6.7 Record an appraisal; 6.8 The appraisals register |
| Policies manual: starter manual, new policy, edit draft, publish version, retire, versions, acknowledgements, supporting documents (Information) | 10.1 Start the policies manual; 10.2 The starter policies; 10.3 Edit and publish a policy; 10.4 Acknowledgements |
| Population reconciled to the people register (Ethics) | 7.6 Reconcile the population |
| Prompt library: default, firm version drafted, approved by owner / administrator, retired (AI assistance) | 19.7 The prompt library; 19.8 Draft a firm version; 19.9 Approve the version |
| Publish a version (SHA-256), changes in a version, compare with now (Risk assessment) | 5.17 Publish a version of the system; 5.18 Versions, and network content; 5.19 Compare a version with now |
| Quality reviews list (Engagements) | 9.12 All engagement quality reviews |
| Quality risks: filters (component, score, assessed, status), new risk, assess likelihood × effect with reasons, residual, owner, reassess date, links to objectives, responses and conditions, evidence (Risk assessment) | 5.3 Find the risks not yet assessed; 5.4 Assess a quality risk; 5.5 Link the risk to objectives, responses and conditions; 5.7 The high risks |
| Raise a concern (anonymously if preferred); concerns raised by name (Complaints) | 14.1 Raise a concern; 14.2 What staff see |
| Raise a concern button (speak-up) (Dashboard) | 14.1 Raise a concern |
| Read and acknowledge a policy (Information) | 10.5 Read and acknowledge a policy |
| Record an external reviewer's completion, withdraw it, review documentation (Engagements) | 9.10 Record a review by a reviewer without a login; 9.11 A report dated before the review |
| Registration numbers (FRC, ICAN, ICAB) and quality management policies (standard, currency, evaluation date, cycle, assembly, retention) (Settings) | 2.2 Registration numbers and quality management policies |
| Regulatory calendar (Information) | 10.8 The regulatory calendar |
| Remedial actions: design, implementation, effectiveness testing by someone other than the owner (Monitoring) | 13.8 Add a remedial action; 13.9 Actions and communication; 13.10 Test that an action works; 13.11 All remedial actions |
| Report to leadership (print, record communication) (Monitoring) | 13.14 Report to leadership; 13.15 Deficiencies in the report |
| Reset another person's two-factor (identity check, own code) and the notice they see (Access) | 3.9 Reset a person's two-factor; 3.10 What the person sees after a reset |
| Responses: specified responses (ISQM 1.34), describe, kind, frequency, owner, status, linked risks, monitoring (Risk assessment) | 5.10 The specified responses; 5.11 Describe a response |
| Restricted entity list and other restricted entities (Ethics) | 7.7 The restricted entity list |
| Retire a risk that does not apply (Risk assessment) | 5.4 Assess a quality risk |
| Review exceptions (cleared / action / return), log as breach finding (Ethics) | 7.4 Review an exception |
| Roles and responsibilities: the four required roles, acknowledgement, time, authority, direct line; issues to resolve (Governance) | 4.1 The four required roles; 4.2 Assign ultimate responsibility; 4.3 Check what is still to resolve; 4.6 Governance complete |
| Root cause analysis: 5 whys, fishbone, categorised causes, positive findings (Monitoring) | 13.6 Root cause analysis: five whys; 13.7 Root causes and the fishbone |
| Schedule a task that operates a response (Risk assessment) | 5.12 Schedule a task that operates a response |
| Search, filters, New, Export CSV, record form with evidence files and history, Delete (Registers) | 6.1 The people register; 6.11 Service providers and due diligence; 16.6 Export a register to a spreadsheet |
| Seat limit from the TroveUniverse plan; banner when all seats are used (Users) | 3.11 When all seats are in use; 3.12 The seats banner |
| Seats bought on troveuniverse.com take effect within a minute (TroveUniverse) | 3.13 Give a regulator read-only access |
| Service providers with due diligence (Resources) | 6.11 Service providers and due diligence |
| Sessions end after 2 idle hours; sign-in throttling (Access) | 1.5 Sign in with your email and password |
| Settings: provider, model, key (sealed), who may use, monthly cap, data minimisation, acknowledgement, switch on, test, remove key (AI assistance) | 19.1 AI assistance is off; 19.2 Provider, model and key; 19.3 Limits, minimisation and acknowledgement |
| Sign by the individual with ultimate responsibility; locked with SHA-256; print; delete a draft (Evaluation) | 15.7 Sign the evaluation; 15.8 Confirm the signature; 15.9 The signed evaluation; 15.10 The evaluations register |
| Sign out (menu); sign-out removes the offline copy (Access) | 20.4 The copy on this device |
| Sign-in page (email, password, Forgot password link, TroveUniverse note) (Access) | 1.5 Sign in with your email and password |
| Signed-in devices; sign out a device or all other devices (Settings) | 2.6 Signed-in devices |
| Single sign-on from troveuniverse.com (first user creates the firm and becomes Owner) (Access) | 1.1 Open SQMTrove from troveuniverse.com |
| Start an evaluation as at the firm's evaluation date (Evaluation) | 15.1 Start the evaluation; 15.2 Choose the evaluation date |
| Subscription notices: grace, suspended (read-only), ended (TroveUniverse) | 22.6 A payment is overdue; 22.7 The subscription is suspended; 22.8 The subscription has ended |
| Switch the link on / off (both apps), direct check, counts (AuditTrove link) | 18.1 The link is off; 18.2 Confirm; 18.3 Linked |
| Technological resources (including AI tools) (Resources) | 6.9 Technological resources |
| Temporary password must be changed at first sign-in (Access) | 1.6 Choose your own password |
| Those charged with governance tracker (listed clients) (Information) | 10.7 Communications with those charged with governance |
| Threats and safeguards (Ethics) | 7.13 Threats and safeguards |
| Traceability matrix (print) (Risk assessment) | 5.13 The traceability matrix |
| Transparency report draft (print) (Information) | 10.10 Draft the transparency report; 10.11 The rest of the draft |
| Two-factor page: status, new recovery codes, move to a new phone (Access) | 2.7 Your two-factor settings |
| Two-factor set-up: intro, QR code, key by hand, recovery codes (download, copy, confirm) (Access) | 1.1 Open SQMTrove from troveuniverse.com; 1.2 Link your authenticator app; 1.3 Save your recovery codes |
| Usage and members reported to TroveUniverse (TroveUniverse) | 3.12 The seats banner |
| Usage log with outcome; CSV (AI assistance) | 19.10 The usage log |
| Working offline: banner, queued changes, sync on reconnect, conflicts and refusals (Offline) | 20.5 Working offline; 20.6 Changes waiting to sync; 20.7 Synced |