AICPA Independence Rules for Nonattest and Attest Services
Separating audit work from client services requires structural walls the code enforces strictly.

Independence in public accounting comes down to one question: can the public trust a conclusion that carries the firm's name? That trust depends on a structural wall between attest work and everything else a firm sells to the same client. AICPA's Code of Professional Conduct builds that wall through a small cluster of rules, and most practitioners who misread them aren't careless. They assume the code's logic runs the same direction as intuition, and that mismatch, not carelessness, is where firms get into trouble.
Audits, reviews, and attestation engagements produce something the public relies on without ever checking the underlying work. That reliance only holds if the practitioner has no stake in the outcome, and "no stake" means more than money: it covers objectivity and skepticism as behaviors, alongside ownership as a fact. Bookkeeping, tax prep, recruiting, advisory work: none of these carry a public-reliance burden on their own. Nobody outside the engagement trusts a conclusion the firm reached about whether a client's payroll runs cleanly. What drags nonattest work into the independence framework is the existence of an attest relationship with that same client. Once a firm signs on to audit or review a client's financials, the rules follow that relationship and start governing everything else the firm might do for the same entity. ET §1.200.001 is the master provision here, and it applies whenever a practitioner delivers attest services as required by whatever standards body oversees that engagement type.
ET §1.295, the Nonattest Services subtopic, activates once that attest relationship exists. It has no bearing on a client the firm serves only for tax returns or bookkeeping; the subtopic stays dormant until an audit or review engagement is on the books for that same client.
The scope runs wider than most practitioners assume, and that's where the surprises start. When the client is a financial statement attest client, §1.295 reaches that client's affiliates too, with a handful of exceptions carved out. A firm auditing a parent company can find its nonattest work for a subsidiary or sister entity pulled into the same analysis. Anyone who treats affiliate relationships as separate business lines gets caught off guard here, since the code was written specifically to close that door.
The list of covered categories runs long, on purpose: advisory services, appraisal and valuation and actuarial work, benefit plan administration, bookkeeping and payroll and disbursements, business risk consulting, corporate finance consulting, executive recruiting, forensic accounting, hosting services, information system services, internal audit assistance, investment advisory or management services, and tax services. Almost any service a firm might bundle alongside an audit lands somewhere on that list. The subtopic is built wide enough that nearly any service a firm might bundle alongside an audit lands somewhere on that list.
The seven threats the code requires practitioners to identify and assess
When the code doesn't spell out an answer for a specific fact pattern, ET §1.210.010, the Conceptual Framework for Independence, fills the gap. It asks one question: would a reasonable, informed third party conclude the threat sits at an acceptable level? That third party is a fiction, but a useful one. It forces the practitioner outside the relationship to judge it the way an outsider would.
Seven threat categories get evaluated under this framework every time, but two of them do almost all the work. Self-review is the one that shows up constantly in practice: it happens when a firm audits evidence that resulted from its own nonattest work, which is exactly what occurs when a firm prepares a client's financial statements and then turns around and audits them. Management participation, taking on decision-making authority at the client, is particularly serious, because bundled-services relationships drift toward it without anyone deciding to cross a line. The other five matter less in daily practice, not because the code treats them as optional, but because they surface far less often. Advocacy means promoting the client's position in a way that compromises objectivity. Familiarity covers relationships with client personnel so close or so long-running that skepticism wears down. Undue influence is client pressure that could bend judgment. Financial self-interest is a direct or indirect stake in the engagement's outcome. Adverse interest covers the member and client ending up on opposing sides of something.
The process runs three steps: identify the relationship or circumstance, name which threat category it falls into, then judge whether it's significant enough to matter. Self-review and management participation surface in the guidance for nearly every service category the code addresses, so a practitioner who has genuinely mastered those two has covered most of the practical ground. Treat the remaining five as equally urgent, and a firm spends its attention where the risk isn't.
The general requirements every firm must satisfy before delivering nonattest services to an attest client
ET §1.295.040 sets four conditions the client has to meet before a firm proceeds with any nonattest engagement. The attest client assumes all management responsibilities. The client designates an individual with suitable skills, knowledge, and experience, shortened to SKE, to oversee the nonattest work. The client evaluates whether the services performed were adequate and reviews the results. The client accepts responsibility for those results.
The SKE standard gets misread often enough to earn its own paragraph, and the misread is almost always the same one. The designated individual doesn't need the expertise to re-perform the work; a client doesn't need someone who could redo the bookkeeping the firm is handling. What the designee needs is enough understanding to oversee the work meaningfully, to ask the right question and recognize a wrong answer when it shows up. A client that designates someone with no relevant background at all, purely to check a box, hasn't satisfied the rule no matter how the engagement letter is worded.
The firm's side of this is categorical, not a matter of degree. A firm cannot assume management responsibilities under any circumstances; it's a bright line, weighed against no safeguards and no set of controls that could rescue it. The code spells out what crossing it looks like: serving as an officer or director of the attest client, accepting responsibility for designing or implementing or maintaining the client's internal controls, or hiring and supervising and terminating the client's employees. These aren't hypothetical edge cases dreamed up for a textbook. They're the exact activities a firm-client relationship drifts toward once a practitioner gets embedded deep enough in day-to-day operations that the boundary starts to blur.
The written documentation requirement and what failure to document actually means
The code requires written documentation before the nonattest work begins, covering the objectives of the engagement, the services being performed, the client's acceptance of its responsibilities, the member's own responsibilities, and any limitations on the engagement.
Its absence is a violation on its own terms, but the nuance that trips practitioners up sits one layer down. Failing to document is treated as a compliance violation distinct from an independence violation, but only if the member can actually show that appropriate safeguards were in place even without a paper trail. If the safeguards weren't applied, the independence violation stands no matter what excuse comes with it.
That distinction has teeth. A practitioner who believes the right safeguards existed but can't produce documentation for them has a compliance problem, which is bad but survivable. A practitioner with neither the documentation nor the underlying safeguards has an independence impairment, a different order of problem entirely. Engagement letters, scope agreements, and written client acknowledgments are the natural tools here, since they create a contemporaneous record that the client actually assumed its share of responsibility before the work started, not after a regulator came asking.
How the rules apply differently across specific nonattest service categories
Bookkeeping, payroll, and disbursements are addressed in the code, covering financial statement preparation, cash-to-accrual conversions, and reconciliations. These sit outside the attest engagement by definition, but the attest engagement may later review the very records the firm just prepared, which makes the self-review threat direct rather than theoretical. Independence survives only when every element of §1.295.040 is met. Skip one, and the engagement is impaired, full stop.
Advisory services are addressed in the code and let a practitioner advise, research, and recommend, but decision-making authority has to stay with the client's management. The rule exists to block self-review and management participation threats, and the operative boundary is the line between advising and deciding. A firm that keeps crossing from one into the other, even informally, has a problem no matter how the engagement letter describes the scope.
Internal audit assistance is one of the higher-risk categories in the whole subtopic, and it's the one firms most often talk themselves into misjudging. Assuming responsibility for the internal audit function creates a significant threat that safeguards may not be sufficient to address. Assistance is fine; direction or control of the function is not, and there's no middle ground the code recognizes here.
Information system services raise concerns around activities that could hand the practitioner management responsibility over a client's financial information system. Self-review and management participation threats are both live at once in this category, which is what makes it harder to safeguard than it first appears.
Hosting services raise a version of this problem that's gotten sharper as cloud practice-management tools have become standard. Independence can be impaired when the member assumes responsibility over an attest client's data or records in a way that creates management participation or self-review threats. Firms that host client files inside cloud-based practice management platforms as a matter of routine face a daily compliance question here, and treating it as an occasional concern, which is still the default posture at plenty of firms, is the mistake. The file sitting in a hosted environment overnight is no different, under the rule, from a ledger sitting in a locked cabinet the firm controls the only key to.
Tax services cover return preparation, transmitting payments, and representing a client before a taxing authority, all addressed directly in the code. More complex tax consulting work has historically had thinner guidance, a gap the code's standard-setting process continues to address.
Why the aggregate of nonattest services creates threats the individual service analysis misses
The code requires a second layer of analysis that looks past any single engagement: whether multiple nonattest services performed for the same attest client, taken together, create a threat so significant no safeguard can bring it back down. A service that looks harmless on its own can tip that aggregate analysis once it's stacked against three or four others.
A firm that prepares financial statements, assists with internal audit work, and consults on information systems for the same audit client sits in a position that's structurally hard to defend as independent, even if each engagement cleared its own threat analysis on paper individually. The aggregate evaluation has to happen before the firm agrees to add a new service, not at year-end and not once the attest engagement is already underway.
The failure mode here is predictable, and it's the one firms fall into most often: they evaluate each new engagement request in isolation as it comes in, without stepping back to ask what the whole relationship looks like to that reasonable, informed third party from the conceptual framework. For firms managing long-term client relationships where services pile up over years, that means periodic reassessment as the mix shifts, a discipline distinct from a one-time check performed when the audit relationship began. A relationship that was clean three years ago can look very different once two more service lines have stacked on top of it. Nobody runs that reassessment automatically. Somebody has to schedule it.
The regulatory layers that can make AICPA rules the floor, not the ceiling
The AICPA Code operates alongside the independence requirements of other regulatory bodies, and failing to meet a more restrictive rule from any applicable regulator counts as a violation even when the firm satisfied AICPA's own standard. Treat the AICPA Code as the starting point, with other regulators' rules layered on top; firms that treat AICPA compliance as the finish line are the ones that get blindsided.
Other regulators impose their own independence requirements on top of the AICPA framework, and firms must identify which ones apply to each engagement. Additional regulatory requirements may apply depending on the nature of the client and the engagement. Certain engagement types bring additional regulatory frameworks into play that layer requirements on top of the AICPA standard. Certain regulatory bodies set their own nonattest services standards that run parallel to §1.295 and apply based on the specific regulatory environment governing the engagement. Additional layers may apply depending on the jurisdiction and regulatory environment, and those requirements need a separate check every time.
The practical discipline follows a simple order of operations: before delivering any nonattest service to an attest client, figure out which regulatory bodies have jurisdiction over the attest engagement itself. The applicable independence standard follows from that answer. Skipping this step is exactly how firms end up compliant with AICPA rules while sitting in violation of PCAOB or SEC requirements that were there the whole time.
How the alternative practice structure model tests the structural boundary between attest and nonattest entities
The AICPA Code has required a clear separation between attest and nonattest entities under outside ownership for more than two decades, and the underlying rule hasn't moved an inch: only a licensed CPA firm can perform attest services. What's changed is the business structure built around that rule.
The alternative practice structure model, which have become more common as firm structures have evolved, splits a single firm into two organizations. One keeps the attest and audit work under CPA ownership, satisfying the licensing requirement. The other houses nonattest services and is free to accept outside capital. Among the largest public accounting firms by U.S. revenue, a significant and growing share have taken private equity backing and adopted APS structures in response, according to CPA Practice Advisor's reporting from February 2025.
Former SEC Chief Accountant Paul Munter flagged the governance gap this creates in a May 2024 statement, noting that private equity investors aren't bound by the same independence and ethical obligations auditors carry. That's the exact tension APS structures are built to manage, and it's exactly why regulators keep scrutinizing them instead of treating the split as settled. The scrutiny is warranted: shared resources, shared personnel, shared branding, and referral relationships between the two halves of an APS can all recreate the same threats §1.295 was written to prevent, just relocated from the engagement level to the organizational level. For a firm operating inside or alongside an APS, the firewall between attest and nonattest entities is a standing structural obligation, one to be maintained continuously rather than revisited only each engagement season.
Where PEEC's active rulemaking is currently updating the independence framework
PEEC issued a multi-part interpretation update in October 2024 touching a range of independence provisions, including revisions to the general nonattest services requirements under ET §1.295.040. The rulemaking reflects a code that hasn't stood still, particularly around the gaps in tax consulting guidance and the newer questions cloud hosting and APS structures have raised. Anyone tracking §1.295 closely should expect the subtopic to keep moving as PEEC works through the areas the current text leaves thinner than the rest of the framework.


