Est.

Accounting Policies and Procedures Template for Tax Firms

Policies set principles; procedures execute them—both are required for a manual that actually works.

Staff Writer · · 16 min read
Cover illustration for “Accounting Policies and Procedures Template for Tax Firms”
Compliance Operations · August 2, 2026 · 16 min read · 3,667 words

The distinction isn't semantic. It's architectural, and getting it wrong is the single most common reason practice manuals fail before anyone opens them.

A policy is the principle: "All client engagements require a signed engagement letter before work begins." A procedure is what that principle looks like on a Tuesday morning in February. Who sends the letter, in what system, by what deadline, and what happens when it comes back unsigned after ten days. A manual built only on policies hands people the "what" without the "how." A manual built only on procedures hands them steps without the governing logic to handle anything the steps don't anticipate. Both halves are necessary. They must travel together, or neither works.

Every section of a functional manual should follow a consistent entry architecture — state the objective, define scope, identify the responsible party by role, provide step-by-step instructions, specify the exception and escalation path. That structure is what makes a manual navigable rather than merely comprehensive. Without it, even a thorough document reads like someone transcribed a staff meeting from memory.

The failure mode practitioners encounter most often is subtler than missing procedures — policies that reflect aspirational workflows rather than actual ones. A procedure nobody follows is worse than no procedure at all, because it creates a paper trail of non-compliance. Before any section is finalized, the drafter should walk through the documented steps with the person who actually performs the work. This sounds obvious. It regularly exposes a gap between what leadership believes happens and what the front desk actually does. That gap is almost always embarrassing, occasionally alarming, and uniformly important. I have been in those conversations more than once, and the surprise never becomes routine. Finding the gap is, in practice, the hardest part of building a manual that holds up under scrutiny, because the people who know about it rarely think of it as a documentation problem until someone from outside the firm starts asking questions.

Venn diagram: Policies vs. Procedures in Practice Manuals. Compares Policies and Procedures; overlap: Both Required.

Client Intake and Engagement Letters: The Section Most Firms Underwrite and Most Claims Expose

The engagement letter isn't a courtesy document. It's the primary liability instrument for a tax practice, and the policy governing it deserves to be written with that weight fully acknowledged.

Scope precision is the most consequential variable, and the one most firms treat as a drafting preference rather than a legal matter. "Preparation of 2025 federal and state personal income tax returns" is a scope statement. "Tax services" is not. That difference in phrasing is the difference between a bounded deliverable and an open-ended obligation a dissatisfied client can stretch retroactively. Every engagement letter must also document the fee structure and what triggers adjustments to it; the source of information relied upon, meaning the firm prepares returns from client-provided documents and independently verifies none of them; the timeline for return completion; and the consequences when information isn't received before the filing deadline. These aren't boilerplate considerations. They are the terms of a professional relationship.

Annual refresh is not optional. A new letter should be issued each engagement year to capture scope changes, fee adjustments, and to limit exposure for prior years. Firms that rely on a single letter across a multi-year relationship are extending their liability quietly, without realizing it, until a claim surfaces and the letter on file is two tax seasons old.

Separate letters should govern distinct services. A client receiving both bookkeeping and tax preparation needs two letters, one for each. This eliminates scope ambiguity and makes it possible to price and manage each service line on its own terms. Combining them feels efficient in October. It generates expensive disagreements in March.

Electronic signatures are legally enforceable under the ESIGN Act and the Uniform Electronic Transactions Act. For IRS-related work, knowledge-based authentication e-signature adds a layer of identity verification that strengthens the instrument further. The policy should state which signature method the firm uses and confirm it meets applicable standards.

The onboarding checklist deserves its own policy entry. The problem in most firms is the absence of a firm-wide standard for how and when to collect the needed information, rather than ignorance of what that information is. Onboarding quality varies by staff member and by season, which means it varies precisely when consistency matters most. The workflow should cover initial contact protocol, the document request list, client portal setup, engagement letter delivery and tracking, and the trigger that formally opens a file. Standardize those steps and busy season becomes at least partly manageable. The chaos doesn't disappear. It just stops being random.

Document Handling, Retention, and Client File Management

Document management is where a firm's operational discipline becomes visible, and where the absence of it creates the most durable exposure.

The document receipt policy must specify who logs incoming materials, in what system, and by what date relative to relevant deadlines. This cannot be a function that depends on whoever happens to be standing near the front when something arrives. It requires a defined responsibility with a defined owner; otherwise it gets handled inconsistently by well-meaning people making reasonable guesses, and eventually something important gets misfiled or missed entirely.

Version control governs how the firm tracks which documents are current, how it handles superseded returns, and how it manages amended filings. Without a formal protocol, files accumulate competing drafts. The risk of working from stale materials rises sharply during high-volume filing seasons, which is exactly when there is no time to sort through a folder looking for the right version. I have watched experienced preparers spend twenty minutes reconstructing which draft is current while a client waits on the phone. The twenty minutes isn't the real cost. The real cost is what it signals about the system holding everything else together.

Naming conventions and folder structure should be standardized to the point where any staff member can locate any file without asking. This matters most during cross-coverage, when someone is unexpectedly out, and in February when new staff are still finding their footing. A firm whose file structure is comprehensible only to the person who built it has built a dependency, not a system.

Retention schedules must be explicit. Client-provided source documents, prepared returns and workpapers, engagement letters, and correspondence each carry different minimum retention periods under IRS guidance and applicable state requirements. Seven years is the commonly cited benchmark for federal workpapers, but state requirements vary and must be verified independently. The manual should list each document type alongside its retention period as a binding firm policy, not a general guideline.

Destruction procedures belong in the manual with the same specificity as retention procedures. Who authorizes destruction, how physical materials are disposed of, how digital materials are permanently deleted, and how the firm documents that destruction occurred should each be assigned and recorded. Undocumented destruction creates the same evidentiary problem as a missing destruction policy, which tends to surprise people at precisely the moment it becomes relevant.

Access policy closes the section. The manual should specify who can view client files, under what circumstances, and how access is logged. This connects directly to the information security requirements addressed later; the language in both sections must be consistent. Staff should be navigating a single, coherent framework rather than two frameworks that contradict each other at the edges.

Revenue Recognition, Billing, and Collections Procedures for Tax Engagements

Revenue recognition in a tax practice is less complex than in other professional service contexts, but it still requires a written policy, and in many firms it simply doesn't have one. When is a tax engagement considered "earned" — at completion, at filing, or at delivery of the return to the client? The answer affects when revenue appears on the firm's books, how unbilled work is tracked, and how write-offs are calculated. It must be documented and must match actual billing timing. Discrepancies between stated policy and actual practice are among the harder things to explain during a financial review, partly because the explanation usually requires admitting nobody ever thought it through in the first place.

Fee structures vary across firms and service lines, and the manual should specify which structure applies to which engagement type. Fixed fees per return type, hourly billing, retainers, and hybrid arrangements each require different procedure entries for invoice generation and reconciliation. A single billing policy applied uniformly across varied engagement types is almost always imprecise, and the friction it generates tends to get attributed to the wrong cause for a surprisingly long time.

The invoice generation procedure should state who creates the invoice, what triggers its creation, in what system it's generated, and within what timeframe after the triggering event. Return delivery is typically the trigger; the invoice should follow within a defined number of business days. Without this, billing lag accumulates quietly and compounds across an entire filing season before anyone notices.

Collections policy requires three components — payment terms stated explicitly in the engagement letter; a late payment escalation sequence with defined intervals and consequences; and a clear written policy on withholding returns pending payment. That last item is the one most firms avoid documenting. If the firm's practice is to withhold a completed return until payment is received, that policy must appear in both the engagement letter and the manual, applied consistently. Inconsistent application creates liability. It also teaches clients to test the rule.

Retainer and prepayment handling requires its own procedure — how deposits are tracked, how they're applied against completed work, how they're reconciled at engagement close. Write-off authorization matters equally. Who can approve a fee reduction or write-off, at what dollar threshold, and how it's documented should all be specified. Without this, undisclosed discounting accumulates and becomes genuinely difficult to explain to a reviewer who notices the pattern.

Payroll, Expense Reimbursement, and Cash Controls Inside the Firm

Tax firms spend considerable energy documenting compliance requirements for clients. They spend correspondingly less time documenting their own internal operations. This gap stays invisible until it isn't, and by then the timing is never convenient.

Payroll cycle documentation should cover timesheet collection, approval, processing cutoff, and disbursement, with each step assigned to a named role rather than a named individual. The firm's own tax reporting obligations as an employer, including W-2 and 1099 issuance, payroll tax deposits, and quarterly filings, should each have a named owner in the manual. A tax firm that leaves its own payroll tax compliance to institutional memory is making a particular kind of bet.

The expense reimbursement policy should define eligible and ineligible expenses with specific examples rather than abstract categories, specify submission format and required documentation, establish approval authority by dollar threshold, set a turnaround time for reimbursement, and describe how missing receipts are handled. Ambiguity here generates more recurring friction than almost any other internal procedure. It resolves cleanly with precise language. That is one of the genuinely satisfying things about building these policies — some problems disappear almost completely once someone commits to writing them down properly, because the act of writing forces the firm to decide what it actually believes.

Credit card policy should address who holds firm cards, what spending limits apply, how frequently reconciliation occurs, and how personal use is prohibited and detected. These elements are individually small. Together they constitute a control environment, and their absence invites exactly the kind of low-level irregularities that are tedious to investigate and uncomfortable to discuss.

Cash controls require the clearest procedural specification in this section, because the failure modes are the most acute. Receiving, counting and recording, and depositing cash should never rest with a single person. Where firm size makes full separation structurally difficult, the compensating controls described in the following section apply directly.

Bank reconciliation should occur monthly at minimum. The procedure should name who performs it, who reviews it independently, and what conditions trigger escalation to the managing partner or an outside reviewer. The reviewer and the reconciler must be different people. Full stop.

Internal Controls and Segregation of Duties When the Firm Has a Small Team

Segregation of duties is the foundational internal control principle. The person who accepts payment shouldn't count and record it; the person who records transactions shouldn't approve them; the person who controls assets shouldn't reconcile them. Three functions — approval, accounting and reconciling, and asset custody — must be separated. The principle has been sound for a long time and nothing about small firm practice changes it.

What small firm practice does change is whether full separation is structurally achievable. Per U.S. Census Bureau data from 2025, firms with fewer than 20 employees represent more than 89% of all employer businesses in the United States. The vast majority of tax practices can't staff classical segregation of duties. This isn't a failure of will. It's arithmetic, and treating it as a moral failing doesn't help anyone build a better control environment.

Compensating controls are the legitimate alternative when structural separation is unavailable, provided they're documented and consistently applied. They are not a consolation prize. They are a real framework with real teeth if constructed properly. The owner or managing partner should review bank statements independently of the person who processes transactions. Dual authorization should be required for transactions above a defined dollar threshold. Reconciliation assignments should rotate periodically. Supervisory review of journal entries and adjustments should be mandatory and documented. The manual should map each compensating control to the specific separation gap it addresses, because that mapping is what an auditor or regulator will look for first. Its absence is conspicuous in ways that are genuinely difficult to recover from.

Access controls are the technical layer of this framework. Unique usernames and passwords are the baseline; multi-factor authentication is required for any platform containing client financial data or firm accounts. The manual should state MFA as a firm requirement, not a recommendation that staff can weigh against inconvenience.

Monitoring controls — regular reconciliations, exception report reviews, budget-to-actual variance analysis — should each carry a named frequency and a named responsible role. A control that exists without a schedule and without an owner is a control that will eventually go unperformed. This is not usually a management failure. It is what happens to unassigned work in any organization: it waits for someone to claim it, and nobody does.

Compliance Requirements That Belong in the Manual by Name: WISP, Circular 230, and the 2024–2025 Regulatory Updates

Table: Key Compliance Requirements for the Practice Manual. Compares Governing Authority, Who It Covers, Key Requirement and Manual Action Required by WISP / FTC Safeguards, IRS Publication 1075, FTC Breach Rule, Circular 230, and 2 more.

Compliance requirements should appear in the manual by name, with a responsible party and a review schedule attached to each. A static list goes stale. The process for keeping the list current is as important as the list itself, and in a regulatory environment that has moved as quickly as this one has over the past two years, that process needs to be explicit and assigned, not left to someone's good intentions.

The Written Information Security Plan is mandatory for all tax professionals under the FTC Safeguards Rule, which derives from the Gramm-Leach-Bliley Act. Since 2023, IRS PTIN renewal applicants have been required to confirm that a WISP exists. The August 2024 update to IRS Publication 5708 added requirements now in effect for the 2026 filing season — universal multi-factor authentication across all systems, passwords of at least 12 characters, a 72-hour breach notification timeline, and explicit vendor contract language covering data security obligations. Each requirement should appear in the manual's WISP section with procedural instructions attached, not merely referenced and left for someone to interpret under pressure.

IRS Publication 1075, effective January 1, 2025, strengthens security and privacy controls for all recipients of Federal Tax Information, including vendors and subcontractors. The manual should document the firm's FTI handling procedures and confirm that vendor agreements have been reviewed for compliance. Publication 1075 also requires role-based security awareness training annually for all employees and treats insider-threat programs as an explicit requirement, not a best practice.

The FTC's 2024 amendment to its breach notification rule requires firms to notify the FTC within 30 days of discovering a breach affecting 500 or more customers. That timeline should be built into the firm's incident response procedure with a named responsible party and a documented escalation path, established before an incident occurs rather than reconstructed afterward under pressure.

Circular 230 governs practice before the IRS. The December 2024 proposed regulations would update its practice standards; the manual should reference the current version and include a policy for monitoring regulatory changes and incorporating them as they finalize. This section cannot be written once and considered finished.

The revised Statements on Standards for Tax Services became effective January 1, 2024. They govern AICPA members and are cited by state boards in enforcement proceedings. The manual's tax practice standards section should reference them explicitly.

The Corporate Transparency Act's beneficial ownership information reporting requirements affect a significant portion of U.S. accounting firms. The manual should assign ownership of CTA compliance tracking to a named role and include a procedure for monitoring developments as enforcement and guidance continue to evolve. This is not a stable area of law. The manual should reflect that instability rather than paper over it.

The consequences of non-compliance are worth stating plainly. FTC investigations, loss of e-file authorization, and state fines are the proximate risks. PCAOB penalties in 2024 totaled $37.4 million, the highest aggregate in the body's history, with individual fines ranging from $25,000 to $50,000. Those figures reflect a regulatory environment that treats documentation failures as substantive violations, not administrative oversights. The manual is the documentation. There is no other document that fills that role when someone is asking.

Quality Management Standards and How SQMS 1 Changes What the Manual Needs to Say

SQMS 1 became effective December 15, 2025, and its significance for the manual is conceptual as much as procedural. The standard moves from a rules-based approach to a risk-based approach for designing, implementing, and monitoring quality management systems. A checklist of procedures no longer suffices. The document must show why each control exists and what risk it addresses. That shift in how a manual must be constructed is genuinely more demanding than the prior model. Firms that fail to understand this distinction discover it at exactly the wrong moment, mid-revision, when someone who knows the standard starts reading what they've built.

Firms that are solely a tax and bookkeeping practice are exempt from the new SQMS standards. The AICPA's Tax Practice Quality Control Guide and Template, available at aicpa-cima.com, applies the same six quality control elements to tax practices and remains the most structurally sound model available to practitioners building or revising a manual. Whether or not SQMS 1 applies directly to a given firm, the framework is worth adopting. It is defensible under external review, and it reflects where the profession is heading regardless of current exemption status.

Each major policy section should be annotated with the risk it mitigates. This serves two purposes. It makes the manual defensible under external review, because the reasoning behind each control is explicit rather than implied. And it makes the manual easier to update, because when a risk changes, the sections addressing it are identifiable rather than scattered across a document someone built three years ago and only partially remembers writing.

The risk-based approach also carries implications for review cadence. A manual designed to address identified risks must be reviewed whenever those risks change — when the firm adds a service line, absorbs significant staff turnover, or faces a meaningful regulatory shift. Annual review is the minimum. The manual should also specify what triggers an unscheduled review and assign responsibility for initiating it. Without that trigger list, annual reviews slide, and the manual drifts from relevance gradually enough that nobody notices until something goes wrong.

How to Structure and Format the Manual So It Gets Used Rather Than Filed

Format isn't secondary. A manual practitioners can't navigate quickly will be bypassed, and a bypassed manual provides no protection regardless of how thorough its contents are.

The entry structure described at the outset — objective, scope, responsible party, step-by-step procedure, exceptions and escalation path — should apply to every section without deviation. Consistency makes the document searchable in practice, not just in its table of contents. When a staff member needs a definitive answer at 4:00 p.m. on April 14, the manual either delivers it immediately or it gets set aside. There is no middle ground on a day like that.

Every responsible party should be identified by role, not by name. A manual that assigns tasks to "Sarah" becomes outdated the moment Sarah leaves. "The engagement manager" or "the partner of record" outlasts any individual and requires no revision on turnover. It's a small decision that pays for itself repeatedly, and firms that skip it relearn the lesson every time someone changes roles.

Version control and effective dates must be built in from the start. Every revision should carry a version number and an effective date. Staff should know where to find the current version and how to confirm it's current. Multiple versions in simultaneous circulation create genuine confusion about which rules apply, and that confusion surfaces at the worst possible moments, reliably.

Accessibility is structural. The manual should live somewhere every staff member can reach without asking. A shared drive location or the firm's practice management system works; a PDF on a partner's desktop does not, regardless of how thorough its contents are.

Training integration determines whether the manual translates into actual behavior. New hire onboarding should include a structured walkthrough, not a self-directed read-and-sign where the new employee nods and moves on to the next form. Cross-training depends on the manual being accurate, current, and genuinely understood by the people performing the work. A manual taken seriously is the curriculum for how the firm operates. One filed away is just paper.

Firms building from scratch should use the AICPA Tax Practice Quality Control Guide and Template as their structural foundation. It provides a documented framework against which a firm can map its own workflows, identify gaps, and build entries that are defensible, current, and actually used.

Sources

  1. financial-cents.com
  2. taxdome.com
  3. financial-cents.com
  4. toaglobal.com
  5. accountants.intuit.com
  6. thetaxadviser.com

More in Compliance Operations