search

Preparing for Peer Review: A CPA Firm's Pre-Audit Checklist

6/18/2026

Peer review preparation goes wrong in a specific way: firms prepare their engagements and are assessed on their system.

That is not true for every firm, which is why the first question matters more than any checklist item.

Which Review Applies to You

The type of review is determined by the highest level of service the firm performs, and it changes what is being examined.

A system review applies to firms performing engagements under the auditing and attestation standards — audits and certain examinations and reviews. The reviewer evaluates the firm's system of quality management, and then selects engagements to test whether that system actually operated. Engagement findings are evidence about the system, not the object of the review.

An engagement review applies to firms whose highest level of service is below that threshold — reviews and compilations. The reviewer evaluates the engagements and the reports themselves, without forming a conclusion on the firm's system.

The practical consequence: a firm subject to a system review that arrives with clean engagements and no documented quality management system has prepared the wrong thing. A firm subject to an engagement review that has built an elaborate system and has report defects has done the same in reverse.

Confirm which applies before preparing.

The Quality Management Shift Firms Are Underestimating

The standards in this area moved from a quality control model to a risk-based quality management model, and firms that treated the change as a renamed manual are exposed.

What the newer approach requires, in substance:

A firm-level risk assessment process — identifying quality risks specific to this firm, its clients, its personnel, and its engagements, rather than adopting a generic list.

Responses designed to those risks, so the firm's policies are traceable to something it actually identified.

A monitoring and remediation process that operates during the year rather than at review time.

An annual evaluation of the system with a documented conclusion, reached by an individual assigned responsibility for it.

Named accountability for the system and for specific components.

The failure mode is a firm with a purchased manual, unmodified, describing a system nobody designed for that firm. A reviewer reads the risk assessment first, and a generic one signals that everything downstream is also generic.

Confirm the effective dates and any transition provisions, since implementation has been phased.

The Pre-Review Checklist

1. Quality management documentation

The risk assessment, the responses, the monitoring process and its results, the annual evaluation and its conclusion, and the assignment of responsibility — in writing, dated, and reflecting this firm rather than a template.

Have evidence the monitoring actually happened. A monitoring process described and never performed is worse than a modest one that was.

2. Independence — where findings concentrate

The most common finding area in practice, and it is documentation rather than substance in most cases.

What to have ready: annual independence confirmations from all personnel; a complete record of non-attest services provided to attest clients; and for each such service, the documented evaluation — the threat identified, the safeguards applied, and confirmation that management accepted responsibility and has the ability and willingness to do so.

The recurring problem: firms perform bookkeeping, prepare financial statements, or assist with a control matter for an attest client, and never document the evaluation. The service may have been entirely permissible; the file cannot show it was considered. Our post on preparing GAAP financial statements covers the substance of that analysis.

Also: partner and staff financial interests, employment relationships, and any fee arrangements requiring evaluation.

3. Engagement acceptance and continuance

Documented for each engagement — the client evaluation, independence check, competence assessment, and the continuance decision for recurring work. Continuance is the part most often undocumented, because nobody re-decides an engagement they have performed for years.

4. Engagement letters

For every engagement, signed, before work began, with language matching the service actually performed. A compilation performed under a review engagement letter, or work performed with no signed letter, is a finding that requires no judgment to identify.

5. Reports

Report defects are the most common engagement-level finding and they are entirely preventable. What to check on every report the firm issued:

The correct report for the service performed. The correct framework referenced, including where a special purpose framework was used. Correct dating, and consistency between the report date and the documentation's completion. Required paragraphs and headings present and correctly worded. Supplementary information reported on where included. Going concern and emphasis-of-matter treatment where applicable. And — a recurring small error with outsized visibility — the firm name and signature presented correctly.

Reading every report issued since the last review, against the current required wording, is a short exercise that removes the most likely finding. Writing Specialized Reports addresses the discipline.

6. Documentation

Complete, assembled within the required period, and evidencing what a reviewer needs to see: planning and risk assessment, the linkage from identified risk to procedure performed, the evidence obtained, conclusions reached, and — critically — evidence of supervision and review, showing who reviewed what and when.

The recurring deficiency is documentation that records conclusions without recording the basis. A file stating that a risk was assessed as low, with nothing supporting the assessment, does not demonstrate that it was assessed.

7. Continuing education

Firm-wide compliance, tracked, including any accounting and auditing hours requirement applicable to personnel working on those engagements. This is a finding a reviewer can confirm in minutes, and it is one of the more embarrassing ones to receive.

8. Consultation and differences of opinion

A documented process, and evidence it was used where a difficult matter arose. A firm that never consults on anything is either unusually simple or not documenting it.

9. Records and retention

Retention policy applied, client records handled appropriately, and — where relevant — evidence of appropriate handling on engagement termination.

10. The prior review's findings

Reviewers check whether the firm did what its previous response letter said it would. A firm that submitted a remediation plan and did not implement it has converted a deficiency into a credibility problem, and repeat findings escalate the outcome.

Expect Certain Engagements to Be Selected

Engagement selection is not random across the whole population. Certain categories are must-select, and specialized engagements fall into them — so a firm with a single employee benefit plan audit, a governmental engagement, or another specialized engagement should assume that engagement will be reviewed.

Two consequences. Prepare the specialized engagement first, since it is the one most likely to be examined and frequently the one performed least often. And consider whether the firm should be performing it at all — a firm doing one specialized engagement annually, with no specific expertise, is carrying disproportionate risk for a single fee.

The Highest-Value Preparation Act

Not the checklist. Pull two completed engagements and review them as a reviewer would.

Take the report, the engagement letter, and the full documentation, and work through them against the applicable standards and the current report wording — as an outsider with no memory of the engagement. Better still, have someone who did not work on them do it, or engage an outside party for a pre-issuance or post-issuance review.

This finds report defects, missing documentation, and independence gaps while there is time to address them, and it is the single most useful thing a firm can do before a review. Firms that skip it discover the same findings from the reviewer, with a follow-up action attached.

The Findings That Recur

In rough order:

Report wording and dating defects.

Independence documentation for non-attest services provided to attest clients.

Documentation of planning and risk assessment, and the linkage to procedures performed.

Evidence of supervision and review.

Engagement letters missing, unsigned, or mismatched to the service.

Accounting and auditing continuing education shortfalls.

Quality management documentation that is generic rather than firm-specific.

Disclosure omissions in financial statements the firm prepared or reported on.

Every one of these is preventable with the self-review above.

Structured coverage is available through the audit training courses catalog, internal auditing training, the Certificate in Financial Reporting and Analysis, the financial statements training listing, Writing Specialized Reports, and ethics training and professional conduct.

Working With the Reviewer

Schedule early. Reviewers have limited capacity in peak periods, and a firm scheduling late takes what is available.

Respond to the information request completely and on time. A reviewer chasing documents forms a view about the firm's organization before examining an engagement.

Be straightforward about known problems. A firm that discloses a deficiency it found itself is in a materially better position than one whose deficiency the reviewer discovers after being told everything was fine. Concealment converts a technical deficiency into an integrity matter, which is a different category of problem entirely.

Ask questions during the review rather than after. Reviewers are practitioners and the conversation is frequently the most useful continuing education a small firm gets.

Afterward

The response letter matters. Where findings are issued, the firm responds with remediation that is specific — what will change, who owns it, and by when. A vague response invites scrutiny at the next review.

Actually do it. Per above, the next reviewer will check.

Treat the findings as information. A firm receiving a documentation finding usually has a systemic documentation practice problem rather than an isolated one, and fixing the practice is cheaper than fixing engagements one at a time.

Where Firms Get This Wrong

  • Preparing engagements for a system review, or a system for an engagement review
  • A purchased quality management manual with a generic risk assessment
  • A monitoring process described and never performed
  • No annual evaluation and conclusion on the system, where required
  • Non-attest services to attest clients with no documented independence evaluation
  • Engagement continuance never re-documented for long-standing clients
  • Engagement letters unsigned, or the wrong letter for the service
  • Reports never re-read against current required wording
  • Documentation recording conclusions without the basis
  • No evidence of supervision and review
  • Accounting and auditing continuing education untracked
  • The specialized engagement left unprepared, when it is the one most likely selected
  • No self-review before the reviewer arrives
  • Prior-review remediation promised and not implemented
  • Concealing a known problem, converting a deficiency into an integrity issue

The summary for a firm principal: confirm which review type applies, read your last two engagements as a stranger would — including the report against current wording — make sure every non-attest service to an attest client has a documented independence evaluation, and check that you actually did what your previous response letter promised. Those four things address most of what reviews find.

Frequently Asked Questions

What determines which type of peer review a firm receives?

The highest level of service the firm performs. Firms performing engagements under the auditing and attestation standards receive a system review, where the firm's system of quality management is evaluated and engagements are selected to test whether it operated. Firms whose highest service is below that threshold receive an engagement review, which examines the engagements and reports without concluding on the system.

What has changed under the quality management standards?

The model moved from quality control to a risk-based quality management approach requiring a firm-specific risk assessment, responses designed to those risks, a monitoring and remediation process operating during the year, an annual evaluation of the system with a documented conclusion, and named accountability. A purchased manual with a generic risk assessment signals to a reviewer that everything downstream is generic too.

Where do findings concentrate?

Report wording and dating defects, and independence documentation for non-attest services provided to attest clients. In the second case the service is often entirely permissible and the file cannot show the evaluation was performed — the threat identified, safeguards applied, and management's acceptance of responsibility documented.

Which engagements will the reviewer select?

Not a random sample of everything. Certain categories are must-select, and specialized engagements fall into them — so a firm with a single employee benefit plan audit or governmental engagement should assume that engagement will be reviewed. It is also worth asking whether a firm performing one specialized engagement annually with no specific expertise should be performing it at all.

What is the single most valuable preparation step?

Pulling two completed engagements and reviewing them as an outsider would — the report against current required wording, the engagement letter, and the full documentation — ideally performed by someone who did not work on them. It finds report defects, documentation gaps, and independence omissions while there is still time to fix them.

Does it help to disclose a problem the firm found itself?

Substantially. A firm that discloses a deficiency it identified is in a much better position than one whose deficiency the reviewer finds after being assured everything was fine, because concealment converts a technical deficiency into an integrity matter. Reviewers also check whether the firm implemented the remediation promised in its previous response letter.

CPATrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@CPATrainingCenter.com
Certifications CPA CFP Enrolled Agent Payroll
Licensing & Events Securities Insurance Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Banking Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All CPA/Accounting Subjects
Facebook Copyright CPATrainingCenter.com 2026