Under the AICPA Code of Professional Conduct, covered member independence rules apply to six categories of people and entities connected to an audit engagement: members of the attest engagement team; anyone in a position to influence the engagement; partners and managers who provide 10 or more hours of nonattest services to the client in its fiscal year; every partner in the office where the lead engagement partner primarily practices; the firm itself, including its employee benefit plans; and any entity controlled by one or more of the above. Anyone in those categories faces strict limits on financial interests, employment, family ties, and services involving the audit client.
Who Counts as a Covered Member
The label reaches well past the people doing fieldwork at the client’s office.
- Every individual on the attest engagement team, from the most junior staff accountant to the lead engagement partner.
- Partners, managers, and others in a position to affect how the engagement is conducted, including quality-control reviewers, supervisors, and anyone providing technical consultation on the engagement.
- Any partner or manager who provides 10 or more hours of nonattest services (tax work, consulting, and similar) to the client during the client’s fiscal year.
- Every partner in the office where the lead engagement partner primarily practices in connection with the engagement, even those with no involvement in the audit.
- The accounting firm as an entity, along with its employee benefit plans.
- Any entity whose policies or operations can be controlled by one or more of the individuals or entities above.
That last category matters more than firms sometimes realize. A side business controlled by an engagement partner is itself a covered member with respect to that partner’s audit clients.
How Long the Designation Lasts
Covered member status runs across the entire period of the professional engagement. It begins when the firm signs the engagement letter or starts performing attest services, whichever comes first, and continues until the later of the final report being issued or the formal termination of the client relationship.
The clock does not reset between annual audits. On a recurring engagement, independence obligations run continuously from the first engagement letter through the end of the relationship. There is no quiet window between last year’s report and next year’s fieldwork in which a covered member can briefly hold client stock or take a prohibited role.
For partners and managers who cross the 10-hour nonattest services threshold, the timing is slightly different. That person remains a covered member until the later of two events: the firm signs the audit report for the fiscal year in which the services were provided, or the person no longer expects to provide 10 or more hours of nonattest services on a recurring basis.
Prohibited Financial Interests
Financial interests are where accidental violations happen most often. The rules treat direct and indirect interests very differently.
Direct Interests Are Always Prohibited
A direct financial interest in an audit client impairs independence no matter how small. One share of client stock, a single client bond, or a partnership interest in the client all qualify. There is no dollar threshold and no materiality exception.
Indirect Interests Depend on Materiality
An indirect financial interest arises when the covered member owns something that itself holds client securities, such as a mutual fund or ETF with a position in the client. Indirect interests impair independence only if they are material to the covered member’s net worth. A small position in a large diversified fund usually will not be material; a concentrated fund with the client as a significant holding could be.
Retirement and Self-Directed Accounts
Retirement accounts, 529 plans, and similar vehicles get no special treatment. If a covered member directs their retirement funds into client stock, that is a direct interest and independence is impaired regardless of the amount. If a plan manager makes the investment decision and the covered member cannot direct it, the interest is indirect and materiality governs. A plan that invests exclusively in the covered member’s audit clients is treated as direct.
Inherited or Unsolicited Interests
Receiving client stock by inheritance or as an unsolicited gift is not an automatic problem. Under SEC rules for public company audits, the covered member must dispose of the interest within 30 days of gaining the right to do so. Holding past that window impairs independence exactly as if the covered member had purchased it.
Loans and Credit Cards
Most loans between a covered member and an audit client or its officers are prohibited because the debtor-creditor relationship undermines objectivity. Limited exceptions exist for certain routine consumer loans, including car loans, loans secured by an insurance policy, and home mortgages, as long as they were obtained through the lender’s standard procedures and on the same terms available to any other borrower.
Credit cards and similar consumer accounts have their own rule. Independence is not impaired as long as the aggregate outstanding balance across all such accounts with the lending institution stays at $10,000 or less on a current basis, taking the payment due date and any grace period into account. Letting a balance climb above that and carrying it past the due date creates a violation.
Services That Impair Independence on Their Own
The 10-hour threshold controls when a partner or manager becomes a covered member. Certain services impair the firm’s independence outright, no matter how few hours are involved. The core rule is that an auditor cannot take on management responsibilities for the client, because that would mean auditing the firm’s own work.
Activities treated as management responsibilities include:
- Setting policy or strategic direction for the client.
- Authorizing or executing transactions on the client’s behalf.
- Preparing source documents that record the client’s transactions.
- Having custody of the client’s assets.
- Making investment decisions for the client or exercising discretionary authority over its investments.
- Designing or implementing internal controls for the client.
- Accepting responsibility for preparing the client’s financial statements under the applicable framework.
A firm can advise and recommend, but the moment it starts making the decisions or doing the work management should be doing, independence is gone. Client management has to review and take responsibility for any work product and must be in a position to make informed judgments about it.
Employment and Business Relationships
A covered member cannot simultaneously hold a key position at the audit client. Key positions include CEO, CFO, controller, chief accounting officer, or a board seat, along with other roles carrying influence over financial reporting. Joint ventures, partnerships, and material vendor or customer relationships between the firm and the client are likewise prohibited.
Cooling-Off for Former Team Members
When someone leaves the audit team to work for the client, a waiting period applies before that person can step into a financial reporting oversight role. For public company audits under SEC and PCAOB rules, the cooling-off period is one year. If the lead partner, concurring review partner, or any team member who provided more than 10 hours of audit-related services takes a financial reporting oversight role at the client inside that window, the firm is no longer independent for that audit.
A financial reporting oversight role reaches further than the CFO title. It covers anyone who can exercise influence over the contents of the financial statements or over the people who prepare them.
Partner Rotation for Public Companies
SEC rules also require the lead audit partner and the engagement quality reviewer to rotate off after five consecutive years. Certain other audit partners are capped at seven consecutive years. Rotation is meant to prevent long relationships from eroding professional skepticism.
Family Members
Financial conflicts do not stop at the covered member personally. The rules treat certain family relationships as extensions of the covered member.
Immediate Family
Spouses, spousal equivalents, and dependents are treated essentially the same as the covered member. A spouse’s holding of client stock impairs independence just as if the covered member owned it. A dependent child in a key accounting position at the client bars the covered member from the engagement.
Close Relatives
Parents, siblings, and nondependent children fall into the close relative category, with narrower rules. Independence is impaired in two situations: when a close relative holds a key position at the client where they could influence its accounting or financial reporting, and when a close relative has a financial interest in the client that is material to the relative’s net worth and the covered member knows about it.
The knowledge requirement matters. A covered member is not expected to know every detail of a sibling’s brokerage account, but reasonable inquiry is expected. Willful ignorance is not a defense.
Trusts, Estates, and Blind Trusts
A blind trust does not shield a covered member. If the trust holds a direct or material indirect financial interest in a client, independence is impaired even though the covered member does not know the specific holdings. The covered member is expected to make sure any blind trust for which they are a beneficiary does not hold interests in their audit clients.
Serving as a trustee or executor raises similar issues. Being named as a future executor of an estate holding client stock is acceptable; actually serving impairs independence. The same rule applies to serving as trustee of a charitable foundation that is the sole beneficiary of such an estate.
Gifts and Entertainment
There is no fixed dollar cap on gifts from a client. A gift impairs independence unless its value is clearly insignificant to the recipient. A branded coffee mug is fine; season tickets are not. Entertainment such as a business dinner does not impair independence as long as it is reasonable under the circumstances, and the same standard applies when the covered member is the one offering gifts or entertainment to the client. Value is the obvious factor, but context matters. A working lunch reads differently from an expensive outing with no business purpose.
When Independence Is Breached
A violation does not automatically destroy the engagement, but ignoring one will. Whoever discovers the breach must promptly report it to the appropriate person at the firm, typically someone responsible for independence policies or the engagement partner. That person evaluates the significance based on factors including the nature and duration of the breach, whether the person who caused it was on the engagement team, whether anyone in firm leadership knew and failed to act, and whether the breach affected the subject matter of the audit.
In less serious cases, removing the individual from the engagement and having their work reviewed by someone unaffected may be enough. In more serious cases, the firm may have to withdraw from the engagement. The test is whether a reasonable, informed third party knowing all the facts would still conclude the firm can issue a credible report.
Enforcement and Which Rules Apply
For private company audits, the AICPA Professional Ethics Division and state boards of accountancy handle enforcement. For public company audits, the PCAOB inspects registered firms and can impose sanctions, and the SEC’s Rule 2-01 of Regulation S-X treats independence violations as separate violations of the securities laws. A firm deemed not independent effectively invalidates the client’s audit, which can trigger restatement and enforcement actions against both firm and client.
Consequences can include substantial fines, mandatory remediation, termination of client engagements, and suspension or revocation of registration. State boards can suspend or permanently revoke an individual CPA’s license.
Which framework applies depends on whether the client is publicly traded. AICPA rules apply to all CPA firms and set the baseline for private company audits. Public company audits add SEC and PCAOB requirements on top, and where the rules conflict, the auditor must follow the most restrictive applicable standard. SEC and PCAOB rules are typically stricter on cooling-off periods, partner rotation, and the scope of prohibited nonattest services. Auditors serving both types of clients keep both frameworks in mind and default to whichever is more demanding for the situation at hand.