Quality control for CPA firms is the internal system of policies and procedures that governs every professional engagement a firm performs, giving the firm reasonable assurance that its people follow applicable professional standards and that the reports and opinions the firm issues fit each client’s circumstances. As of December 15, 2025, the AICPA replaced its older rules-based framework with a risk-based approach that requires firms to identify and respond to specific threats to engagement quality rather than working from a fixed checklist.
Which Rulebook Applies to Your Firm
Two bodies set quality control requirements, and jurisdiction depends on the clients a firm serves. The American Institute of Certified Public Accountants (AICPA) sets the foundational standards for firms serving privately held companies, nonprofits, and government entities. Every AICPA member firm must comply, and the AICPA enforces those requirements through its peer review program.
Firms that audit publicly traded companies answer to the Public Company Accounting Oversight Board (PCAOB), which requires registered firms to adopt a quality control system that provides reasonable assurance of compliance with its auditing standards.1Public Company Accounting Oversight Board. AS 1110 – Relationship of Auditing Standards to Quality Control Standards Many larger firms answer to both regimes at once because they audit a mix of public and private clients.
The Eight Components of the AICPA System
The AICPA’s Statements on Quality Management Standards (SQMS No. 1, No. 2, and No. 3) took effect on December 15, 2025, replacing the older Statement on Quality Control Standards.2AICPA & CIMA. A Journey to Quality Management The shift is philosophical. Instead of maintaining six fixed quality control elements, firms now operate under a risk-based system built around eight interconnected components. The firm identifies specific risks to engagement quality, designs responses, and continuously monitors whether those responses work.
SQMS No. 1 organizes the quality management system into these components:
- Risk assessment process. The engine of the system: identify quality objectives, assess what could go wrong, design responses.
- Governance and leadership. Senior partners set the culture and assign operational responsibility for the system to a designated individual.
- Relevant ethical requirements. Policies covering independence, integrity, objectivity, and confidentiality across all engagements.
- Acceptance and continuance of client relationships. Evaluating whether the firm can serve a client competently and ethically before agreeing to the work.
- Engagement performance. Planning, supervision, consultation on complex issues, and review at every level.
- Resources. Staffing, technology, and intellectual resources sufficient for the firm’s practice.
- Information and communication. Ensuring quality-related information flows to the right people inside and outside the firm.
- Monitoring and remediation. Ongoing evaluation of whether the other components function, with corrective action when they don’t.
SQMS No. 2 sets standards for engagement quality reviews, defining when a second partner must independently evaluate an engagement before the report is issued. SQMS No. 3 provides conforming amendments to the first two standards.
What This Looks Like in Practice
Leadership is where the system starts. Managing partners have to create a culture where doing the work right takes priority over doing it fast or cheap. That means naming a specific partner with operational responsibility for the quality management system, budgeting time for technical consultation on complex engagements, and structuring compensation so partners are not rewarded for cutting corners.
Independence is the single highest-risk area for assurance engagements. If a firm or its people hold a financial interest in an audit client, the engagement is compromised. The system must track every financial relationship between firm personnel and clients, including investments, loans, and family relationships. Personnel typically sign annual affirmations confirming they have no prohibited relationships. The AICPA’s Code of Professional Conduct sets the underlying rules for confidentiality, objectivity, and professional competence, and Circular 230 layers additional ethical requirements on tax work.3Internal Revenue Service. Office of Professional Responsibility and Circular 230
Client acceptance sits earlier in the workflow than most people realize. Before taking on a new engagement or continuing an existing one, the firm evaluates whether it has the technical competence for the work, whether the client’s management has integrity issues that create unacceptable risk, and whether independence requirements can be met. The right move on a bad fit is to decline the engagement, not to deliver substandard work.
Staffing has to match engagement complexity. A first-year associate should not run a complicated revenue recognition analysis without supervision from someone who has done it before. Continuing education keeps skills current: AICPA members must complete 120 hours of CPE every three-year reporting period, and most state boards impose their own annual requirements on top.4AICPA & CIMA. AICPA Membership CPE Requirements
Engagement performance is where quality either holds or breaks. The engagement partner bears final responsibility for the work and the report. Consultation is mandatory for unusual matters. Work papers must document the procedures performed, the evidence gathered, and the reasoning behind the conclusions. Vague or incomplete documentation is one of the most common deficiencies inspectors flag, because if it isn’t in the work papers, it effectively didn’t happen.
What Changes for PCAOB-Registered Firms
The PCAOB currently operates under interim quality control standards it adopted in 2003 from the AICPA’s older framework.5Public Company Accounting Oversight Board. Quality Control Standards Those interim standards organize quality control around five elements: independence, integrity, and objectivity; personnel management; acceptance and continuance of clients; engagement performance; and monitoring.6Public Company Accounting Oversight Board. QC Section 20 – System of Quality Control for a CPA Firm’s Accounting and Auditing Practice
That framework is being replaced. QC 1000, a new risk-based quality control standard, takes effect on December 15, 2026.7Public Company Accounting Oversight Board. QC 1000, A Firm’s System of Quality Control It requires firms to establish quality objectives, identify and assess quality risks each year, design responses, and run a monitoring and remediation process. Firms must evaluate the effectiveness of their system annually as of September 30 and report on that evaluation. Firms that undergo annual PCAOB inspections also have to maintain an external quality control function as an independent check on the system.
Once QC 1000 is live, both AICPA and PCAOB frameworks will follow the same risk-based philosophy, which reduces friction for firms that straddle both regimes.
How the Requirements Shift by Service Line
A quality management system is not one-size-fits-all. The risks change with the type of work.
Audit and Assurance
Independence controls are tightest here because third parties rely on the firm’s opinion. The system requires detailed documentation of every technical consultation, strict evidence-gathering standards, and, under SQMS No. 2, an engagement quality review for high-risk engagements. Public company audits also have to comply with PCAOB auditing standards, which add documentation and review requirements on top of the AICPA rules.
Tax
Tax work has its own risk profile. Due diligence standards require a documented basis for every position taken on a return. The firm must comply with Circular 230, and under 31 CFR 10.36 the individual with principal authority over a firm’s tax practice can be personally disciplined for failing to maintain adequate compliance procedures if practitioners at the firm engage in a pattern of noncompliance.8eCFR. 31 CFR 10.36 – Procedures to Ensure Compliance That personal exposure is what gives “tone at the top” real teeth in tax practice. Training has to keep pace with law changes, and the system must address the risk of preparer penalties for unreasonable positions.
Consulting and Advisory
Advisory engagements often demand specialized knowledge in areas like cybersecurity, business valuation, or transaction structuring. The system must verify that assigned staff have documented expertise. Engagement letters defining scope carry extra weight here, because advisory work can expand in unpredictable ways and drag the firm into liability it never agreed to accept. Conflicts of interest need close attention when the firm advises on transactions involving entities it also audits.
How Long Records Must Be Kept
Quality control doesn’t end when the engagement wraps. For public company audits, the Sarbanes-Oxley Act directs auditors to retain all audit or review work papers for a minimum of seven years, and destroying audit records before that window closes can carry criminal penalties.9U.S. Securities and Exchange Commission. Retention of Records Relevant to Audits and Reviews State boards and professional standards generally require shorter retention periods for non-public engagements, though many firms apply the seven-year rule across all engagements as a practical safeguard.
External Checks: Peer Review and PCAOB Inspections
Internal monitoring is only half the picture. Both regulators impose outside checks.
Firms that perform accounting or auditing work must undergo a peer review every three years. An independent CPA firm examines the quality management system and a sample of completed engagements, then issues a report with one of three ratings: pass, pass with deficiencies, or fail. Anything below pass typically triggers corrective action requirements and can affect the firm’s ability to keep certain clients or stay enrolled in AICPA practice-monitoring programs.
PCAOB-registered firms face a tougher process. The PCAOB inspects firms that audit more than 100 public companies every year and inspects smaller registered firms at least once every three years.10Public Company Accounting Oversight Board. Basics of Inspections Inspectors review individual engagements and evaluate the firm’s quality control system. When they find quality control defects, the firm gets 12 months to fix them. If the firm doesn’t address the criticisms to the Board’s satisfaction within that window, the deficiency findings become public.11Public Company Accounting Oversight Board. Remediation In serious cases, the PCAOB can impose sanctions including censure, civil money penalties, and temporary or permanent bars on individual practitioners.
What Happens When the System Fails
A weak quality control system is an existential problem for the firm. A missed procedure produces a deficient inspection report. Deficiencies go public. Clients and audit committees start asking uncomfortable questions. Competitors recruit the strongest staff, who don’t want the stigma. Insurance premiums climb. At the extreme, the PCAOB can revoke a firm’s registration and state boards can suspend or revoke the firm’s license.
The stakes are personal too. Under PCAOB disciplinary proceedings, auditors have been censured, fined tens of thousands of dollars, and barred from association with registered firms for quality-related failures. Under Circular 230, the individual overseeing a tax practice can be personally disciplined for a pattern of firm-wide noncompliance even when they didn’t personally prepare the problematic returns.8eCFR. 31 CFR 10.36 – Procedures to Ensure Compliance The “tone at the top” language in the standards is a rule with real consequences attached, not aspiration.