ISQM 1 evaluation cycle ACTIVE lobal
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
PDPL fully enforceable — SAR 5M exposure
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
ISQM 1 evaluation cycle ACTIVE — global
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
ISQM 1 evaluation cycle ACTIVE lobal
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
PDPL fully enforceable — SAR 5M exposure
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
ISQM 1 evaluation cycle ACTIVE — global
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
The five frameworks on the right are the constants — what every audit firm in every IFAC-member territory is now expected to evidence. falconry.one imports them as control libraries, then maps them to your firm-specific quality manual and your engagement workflow.
What that means in practice: when a regulator updates ISQM 1 guidance, or IESBA revises an independence rule, or NIST publishes CSF 2.0, your control library and evidence templates update with it. You don’t have to commission a re-mapping project — that’s our job.
Every clause-to-control link is timestamped. Every regulatory revision triggers a partner-level alert with a “what changed and what to do” summary, written by Falconry’s regulatory team — not a vendor newsletter.
System of Quality Management — eight components, mandatory for IFAC-member firms
Engagement Quality Reviews — workflow, threshold rules, sign-off
Quality Management for an audit of financial statements
International Code of Ethics for Professional Accountants — independence, conflicts
Information security management — control library mapping
Cyber Security Framework — Govern function included
Risk management principles — enterprise risk register
Business continuity — for the resilience module
SOCPA
Saudi Organization for Chartered Professional Accountants — peer review, ISQM 1, CPD
UAE MoE
UAE Ministry of Economy auditor licensing requirements
QFCRA
Qatar Financial Centre auditor regulation
CMA
KSA Capital Market Authority — listed entity audit oversight
PDPL (KSA)
Personal Data Protection Law — enforceable, regulator-active
UAE PDPL
UAE Federal Decree-Law on data protection
QFC DPL
Qatar Financial Centre Data Protection Regulations
NCA ECC
Saudi National Cybersecurity Authority Essential Controls 2024/25
SAMA CSF
Saudi Central Bank Cyber Security Framework — financial sector
UAE SIA
UAE Signals Intelligence Agency cyber controls
SDAIA
Saudi AI & Data Authority — AI governance guidance
FRC AQR
Financial Reporting Council — Audit Quality Review regime
ICAEW
Institute of Chartered Accountants — practice assurance, CPD
ACCA
Association of Chartered Certified Accountants — monitoring, CPD
IAASA (IE)
Irish Auditing and Accounting Supervisory Authority
UK GDPR
Post-Brexit UK General Data Protection Regulation
DPA 2018
UK Data Protection Act 2018 — DPO, RoPA, DPIA
PECR
Privacy and Electronic Communications Regulations
NCSC CAF
National Cyber Security Centre — Cyber Assessment Framework
ECCTA
Economic Crime & Corporate Transparency Act — failure to prevent
SMCR (FCA)
Senior Managers and Certification Regime — for regulated audit firms
IRBA (SA)
Independent Regulatory Board for Auditors — South Africa
FRC Nigeria
Financial Reporting Council of Nigeria — auditor oversight
ICPAK
Institute of Certified Public Accountants of Kenya — practice review
EFSA
Egyptian Financial Supervisory Authority — listed entity audit
POPIA (SA)
Protection of Personal Information Act — South Africa
NDPR (NG)
Nigeria Data Protection Regulation — NITDA-supervised
DPA Kenya
Kenya Data Protection Act 2019 — ODPC enforcement
SARB CYBER
South African Reserve Bank cyber resilience standards
FATF
FATF-aligned AML programmes — across the region
CEAOB
Financial Reporting Council — Audit Quality Review regime
PANA / KIBR
Poland: PANA + Polish Chamber of Statutory Auditors
RVH
Czech Republic — Audit Public Oversight Council
ASPAAS
Romanian Authority for Public Oversight of Statutory Audit
EU GDPR
European General Data Protection Regulation
DSA / DMA
Digital Services Act / Digital Markets Act — where in scope
NIS2
EU Network & Information Security Directive 2 — in scope
EU AR
EU Audit Reform regime — PIE rotation, fee caps, NAS prohibitions
DORA
Digital Operational Resilience Act — for financial sector audits
ISQM 1 / SoQMSystem of quality management evaluationISQM 2 / EQREngagement quality review workflowIndependence (IESBA)Confirmations, restricted entity registerLocal audit regulatorSOCPA / FRC / IRBA / CEAOB peer + AQRLocal data protectionPDPL / UK GDPR / POPIA / EU GDPRLocal cyber controlsNCA ECC / NCSC CAF / NIS2 / SARBListed entity auditCMA / FCA / DTI / EU AR oversightSectoral cyber (financial)SAMA CSF / DORA / SARBAI governanceSDAIA / EU AI Act / NIST AI RMFAML / UBOFATF aligned client acceptanceEvery Monday, the regulatory team reviews the previous week's issuances across the markets we serve. Material items are tagged, summarised, and routed to affected customer firms.
Mapping refreshes are pushed monthly to all customer instances. Material changes are accompanied by a partner-level alert with "what changed and what to do" guidance.
A 30-minute quarterly briefing per region for customer Quality Partners. Covers the live regulator pipeline, expected enforcement themes, and platform updates that respond.
When an FRC, SOCPA, IRBA, ICPAK or AQR letter lands, the regulatory team is on standby. Available as standard support for Networks tier; retainer-activated for other tiers.
A live walkthrough of an ISQM 1 SoQM evaluation on the platform — against your firm's existing manual and inspection history. You see exactly what the partner view looks like, what the evidence pack contains, and what the 8-week deployment would mean for your cycle.