Nonattest services are any professional services a CPA firm provides that do not involve issuing an assurance opinion: tax preparation, consulting, bookkeeping, valuations, technology advisory work, forensic investigations, and everything else outside the audit or review itself. For a firm that also audits the client, these engagements raise a specific problem. They can put the firm in the position of auditing its own work, making management decisions, or advocating for the client, any of which destroys independence. The rules that govern how far a firm can go depend on whether the audit client is publicly traded or private, and the two regimes are not close.
Attest Work Versus Everything Else
Attest services are engagements where a CPA examines information someone else prepared and issues a formal opinion or conclusion about its reliability. Financial statement audits are the familiar example. Reviews of interim financial data and examinations of prospective financial information also qualify.
Everything else a CPA firm does for a client is nonattest work. Preparing tax returns, advising on mergers, helping pick accounting software, performing business valuations, running forensic investigations, general consulting. The difference is straightforward: in attest work, the CPA opines on someone else’s numbers; in nonattest work, the CPA produces numbers, gives advice, or builds systems.
Trouble starts when the same firm does both for the same client. If the firm preparing the data is also auditing the data, it is grading its own homework. Regulators call this a self-review threat, and it sits underneath almost every independence rule written.
Who Sets the Rules
Three overlapping authorities govern auditor independence, and which one controls depends on the client.
For private companies, the AICPA’s Code of Professional Conduct is the primary authority, and most state boards of accountancy have adopted it or built rules on it.1AICPA & CIMA. Professional Responsibilities The approach is principles-based: the firm identifies threats and applies safeguards engagement by engagement.
For publicly traded companies (issuers), the Sarbanes-Oxley Act gave the SEC authority to define independence standards and created the PCAOB to oversee the audits.2U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence Those rules are prescriptive. They list specific prohibited services rather than leaving the analysis to the firm. The PCAOB enforces them and layers on its own standards, particularly for tax work.3PCAOB Public Company Accounting Oversight Board. Ethics and Independence Rules Where the federal rules conflict with the AICPA’s, federal rules win for issuer audits.
Nine Services a Public Company Auditor Cannot Provide
Section 201 of the Sarbanes-Oxley Act prohibits a registered accounting firm from providing any of nine categories of nonattest services to a public audit client while the audit is going on.4Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements Providing any of them makes the firm not independent as a matter of law, which invalidates the audit opinion.
- Bookkeeping and related accounting services. The firm cannot maintain the client’s accounting records or prepare financial statements that will later be audited. The SEC has said all bookkeeping services destroy independence unless it is reasonable to conclude the results will not be subject to audit procedures.5U.S. Securities & Exchange Commission. Final Rule: Strengthening the Commissions Requirements Regarding Auditor Independence
- Financial information systems design and implementation. Building, designing, or implementing any system that feeds the client’s financial statements or internal controls is off limits.
- Appraisal or valuation services, including fairness opinions and contribution-in-kind reports. The concern is that the firm would be auditing its own estimate.4Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements
- Actuarial services. Common in insurance and pension contexts, and prohibited because the outputs flow into audited figures.
- Internal audit outsourcing. The external auditor cannot also be the client’s internal audit function.5U.S. Securities & Exchange Commission. Final Rule: Strengthening the Commissions Requirements Regarding Auditor Independence
- Management functions or human resources. The firm cannot act as a director, officer, or employee, and it cannot make hiring decisions for positions that oversee financial reporting, such as controller or CFO.
- Broker-dealer, investment adviser, or investment banking services. These create conflicting financial interests that are incompatible with objectivity.
- Legal services and expert services unrelated to the audit. The auditor cannot serve as a legal advocate for the client or provide expert testimony supporting the client’s position in litigation or regulatory proceedings.
- Any other service the PCAOB determines is impermissible. A catch-all that lets the Board expand the list as new threats appear.4Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements
Any nonattest service not on this list can still be provided to a public audit client, but only if the audit committee pre-approves it. Sarbanes-Oxley requires pre-approval of every service, audit or non-audit, before the work begins.2U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence
Tax Services for Public Audit Clients
Tax compliance work is not on the prohibited list, so a firm can generally prepare a public audit client’s corporate returns and advise on tax positions. The PCAOB has added restrictions that firms miss regularly.
PCAOB Rule 3523 states that a firm is not independent if it provides tax services to anyone in a financial reporting oversight role at the audit client, or to that person’s immediate family. That covers the CFO, chief accounting officer, controller, and comparable positions. The restriction runs throughout the entire audit and professional engagement period, starting when the firm signs the engagement letter or begins audit work (whichever comes first) and ending only when the client-auditor relationship formally terminates.6PCAOB Public Company Accounting Oversight Board. Concept Release Concerning Scope of Rule 3523, Tax Services for Persons in Financial Reporting Oversight Roles
Even for permissible tax services, PCAOB Rule 3524 requires the auditor to describe the engagement in writing to the audit committee, discuss the potential effects on independence, and document the substance of the committee’s discussion before work begins. That goes beyond the general pre-approval requirement; the firm has to walk the committee through the independence implications of the specific tax work being proposed.
What Private-Company Auditors Can Do
The AICPA’s approach is more permissive, and private-company auditors have room to provide consulting, bookkeeping, and advisory work to audit clients. The trade-off is that the firm carries the burden of analyzing every engagement for threats and building adequate safeguards.
Under the Code of Professional Conduct, a CPA firm can perform bookkeeping, prepare financial statements, and provide services that would be flatly prohibited on the public-company side, provided the firm does not take on management responsibilities. The client must designate a person in senior management with suitable skill, knowledge, or experience to oversee the firm’s work. That person does not have to be able to re-perform the service, but they must be capable of evaluating the results and making all substantive decisions.7American Institute of Certified Public Accountants (AICPA). Code of Professional Conduct
Some activities cross the line under any framework. A firm impairs its independence if it prepares source documents like purchase orders, takes custody of client assets, or supervises client employees in their day-to-day work. Those make the firm a de facto part of management no matter how the engagement letter reads.
The practical difficulty in smaller companies is that the client may not have anyone on staff who can meaningfully oversee the CPA’s nonattest work. When that happens, the designated-competent-individual safeguard is hollow and the firm is effectively making management decisions by default. Most independence problems in private-company engagements start there, not with deliberately prohibited work but with a gradual drift into a management role no one formally acknowledges.
Safeguards That Have to Be in Place
When a nonattest service is allowed, the firm has to build a wall between the advisory work and the audit opinion. The specifics vary by framework, but the core safeguards are consistent.
The most important one is that the client keeps management responsibility. The client makes every substantive decision; the firm advises, recommends, and executes. This cannot be a formality. If the client’s designated oversight person signs off on whatever the firm recommends without real evaluation, the safeguard has failed and the firm has participated in management.
For public-company audit clients, the audit committee has to pre-approve the specific service before it starts, including the scope and estimated fees, with enough information to assess whether the engagement compromises objectivity.2U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence
Firms should document several things before starting work: the objectives of the engagement, the services to be performed, the client’s management responsibilities, the firm’s responsibilities, and the limitations of the engagement. For private-company work, this understanding belongs in an engagement letter. That documentation is the firm’s primary defense if a regulator later asks whether the service crossed into management participation.
Internally, the firm has to assess whether the engagement creates any unacceptable threat under the relevant framework and conclude in writing that the service can be performed without impairing independence. If the threat cannot be reduced to an acceptable level through safeguards, the firm must decline the engagement or resign from the audit.
What Happens When a Firm Gets It Wrong
Independence violations carry consequences that can end careers and damage firms.
The PCAOB can impose censures, monetary penalties, and limitations on a firm’s or an individual’s ability to audit public companies or broker-dealers.8PCAOB Public Company Accounting Oversight Board. Enforcement At the extreme, the Board can permanently bar an individual from public-company audit work. Firms face the same range of sanctions, and for large firms the reputational damage from a public PCAOB enforcement action often exceeds the financial penalty itself.
The SEC can act under Rule of Practice 102(e), which allows the Commission to censure, suspend, or permanently bar an accountant from appearing or practicing before the SEC. A practice bar effectively prevents the person from doing any work related to the financial statements of a public company or its affiliates. The SEC can also issue cease-and-desist orders and impose civil monetary penalties.
The AICPA’s Joint Trial Board can expel or suspend members for up to two years. During a suspension, the member cannot identify as an AICPA member on letterhead or other materials, cannot vote in AICPA matters, and cannot hold committee positions. For less severe violations, the AICPA may issue a public admonishment or require corrective action such as additional continuing education. Both expulsions and suspensions are published publicly.9AICPA & CIMA. Definitions of Ethics Sanctions/Disposition
The formal sanctions are only part of it. If the SEC or PCAOB determines the auditor lacked independence, the audit opinion is invalid. The public company may need to be re-audited by a different firm, which delays SEC filings, creates delisting risk, and shakes investor confidence. For the audit firm, losing a major client under those circumstances sends a signal to every other client and every prospect in the market.