Est.

Quality Control Processes in Tax Compliance Operations

Systematic errors in tax work stem from design flaws, not careless mistakes.

Features Editor · · 10 min read
Cover illustration for “Quality Control Processes in Tax Compliance Operations”
Compliance Workflows · August 21, 2026 · 10 min read · 2,255 words

Most tax firms treat errors as bad luck: a preparer had a rough week, a client sent bad documents, someone missed a deadline under pressure. The data says something else. Improper payment rates on the Earned Income Tax Credit, payroll penalty statistics, and a nine-year high in withdrawn financial statements all point the same way: errors in tax compliance work follow patterns, and a pattern is a design problem, not a personnel one.

The IRS puts the EITC improper payment rate somewhere between 22% and 26% of all payments. Dig into the agency's own study of 2006 through 2008 returns and the number gets worse: 28.5% to 39.1% of claimed EITC dollars were over-claims, somewhere between $14.0 billion and $19.3 billion. Three-quarters of the qualifying-child errors in that study came down to one thing: misclassifying residency. That's one failure point repeating at scale, not a thousand scattered mistakes. Somebody could have built a single check for it and stopped a huge share of the problem cold. Nobody did.

The pattern shows up well outside the IRS's own books, too. The American Payroll Association's 2025 survey put manual payroll processing at an average of 3.2 filing errors a year per organization, at roughly $4,800 per penalty, landing around $15,360 a year for a mid-size employer. A 2024 FDIC Employment Tax Compliance Study found that companies filing in five or more states eat payroll tax penalties at 2.9 times the rate of single-state filers. Withdrawn financial statements tied to public accounting errors hit a nine-year high in 2024, at firms where review and sign-off had already happened. The mistakes still got out the door. Error prevention that's informal, or shoved to the back end of the process, just doesn't hold.

What "quality control" actually means in a tax compliance context

Ask most practitioners what quality control means and you'll get some version of "the partner reviews it before it goes out." That's a layer. Mistaking a layer for a system is where most of this goes wrong.

A tighter definition from the internal controls literature treats tax compliance controls as the policies, workflows, approvals, permissions, and monitoring that keep obligations complete, accurate, timely, authorized, and documented. Timeliness is one item on a five-item list, and a return can go out on the due date while the control environment underneath it is a mess: nothing validated, a payment released without proper sign-off, a review that happened but never got written down anywhere, an entire process resting on the one employee who knows where everything lives, no backup if she's out sick or gives two weeks' notice.

The IRS's own Quality Assurance Review program describes quality assurance in nearly identical terms: spot unsatisfactory trends and defects, then fix the underlying cause through administrative, analytical, and practical methods. That's a standing corrective function, a different posture entirely from a single inspection before shipping. For a practitioner, the takeaway is blunt: where the checks sit inside the workflow matters more than whether a check exists somewhere before filing.

How the IRS structures its own layered QC system — and what practitioners can learn from it

The IRS doesn't run one review pass. An agency processing hundreds of millions of returns a year runs several parallel, interlocking quality programs instead of a single gate at the end, and that alone is worth sitting with for a second.

The Embedded Quality program covers Accounts Management, Campus Collection, Campus Examination, Field Assistance, Return Integrity and Compliance Services, Tax Exempt and Government Entities, and Electronic Products and Services. Quality sits inside each operational unit itself, built into the daily work rather than farmed out to some separate department that checks everyone else's output after the fact.

Then there's the Quality Assurance Review program, which samples program evaluations, managerial reviews, operational reviews, and security reviews to see whether internal controls actually get followed in practice, not just written down somewhere. This sits a level above the first program; it checks whether the quality process itself works, not whether one case came out fine. Per IRM 02-005-014, the IRS runs separate review types for IT and application development, including a process area review for adherence to standards and a work product review checked against defined templates, designed to measure quality systematically rather than through ad hoc spot-checks.

On top of all that sits the Internal Control Managerial Assessment, done every year by every business unit head. Accountability for quality sits with operational leadership, not with a quality office down the hall that nobody else has to think about. The lesson for private practice is structural: separate the process-level checks from the product-level checks from the systemic trend analysis. Running one big undifferentiated review at the end is the tax-firm version of trying to catch every factory defect by inspecting the finished product and hoping for the best.

The three stages where QC checks belong: intake, preparation, and sign-off

Diagram: Three Stages, One QC System: Where Checks Actually Belong. Visualizes: Show a linear three-stage workflow — Intake, Preparation, Sign-off — where each stage carries its own named checks.

Most practices have some version of a sign-off review. Almost none have formal checks at intake or partway through preparation. That gap is exactly where most errors get born.

Intake is where incompleteness and inconsistency get caught before anyone starts working the file. That means a real checklist for document completeness, validation of entity type and filing requirements, a flag for multi-state nexus, and a comparison against prior-year data to catch anything that looks off. Go back to that EITC residency error behind 75% of the qualifying-child mistakes in the IRS study: a structured intake screen built around qualifying-child eligibility rules would have caught that entire category before a single return was touched. Engagement documentation and authorization belong here too, and they aren't paperwork overhead. They're quality controls in their own right.

Preparation is where recurring decisions get handled the same way every time and in-process errors get flagged before a reviewer ever sees the file. That means cross-checking source documents against entries, verifying calculations, flagging positions that need technical support, and applying jurisdiction-specific rules for multi-state filers. Sound practice in this stage means firms maintain standard procedures for how preparers document the basis of the positions they take, a record of how the calls inside a return got made, not just proof a return got prepared. This is also where a second set of eyes costs the least. Catching something mid-preparation is cheaper than catching it after, which sounds obvious until you notice how few firms actually build in that mid-point check.

Sign-off and final review should confirm the earlier controls worked, not substitute for them. The checks here are reviewer independence (someone other than the preparer actually looks it over), documentation completeness, disclosure adequacy, technical review on higher-risk items, and authorization before anything gets filed. When sign-off is the only QC layer a firm has, reviewers stop confirming quality and start hunting for defects, which is a far heavier lift. Under real deadline pressure that lift becomes unsustainable, and errors slip through anyway. The nine-year high in withdrawn financial statements from 2024 is about as direct a signal as you'll get that sign-off alone isn't holding up under current staffing.

Why staffing pressure and the talent gap are actively degrading QC in many firms

The accounting profession is losing practitioners to retirement and departure faster than new graduates can replace them, a trend widely documented in industry reporting. Firms get asked to do more with fewer hands, and something has to give.

What gives, almost every time, is the early-stage QC work. Intake screens get skipped when the team's underwater. Mid-preparation checks go informal, then quietly stop happening at all. The sign-off reviewer ends up absorbing everything that was supposed to be spread across the workflow, and one person catching every mistake at the finish line isn't a plan. It's a hope.

There's outside pressure too. The IRS lost 25,386 employees in fiscal year 2025, about a quarter of its workforce, including experienced staff who handle complex compliance work. That can breed a false sense of security, since fewer audits can feel like lower stakes for QC failures. But the IRS's Automated Underreporter Program matches information returns against filed returns with no revenue agent anywhere in the loop; mismatches generate notices no matter how thin the agency gets on staff. Enforcement wasn't slowing down before the cuts, either. IRS collection activity climbed 13.6% in fiscal year 2024, to nearly $77.6 billion, which tells you enforcement was already concentrating in high-yield categories well before the workforce shrank. Firms are getting squeezed on staffing at the same moment the enforcement posture around them is shifting, and QC systems built for calmer years on both fronts need rethinking now, not after the next wave of penalty notices lands. Thin QC infrastructure leaves firms more exposed than they realize, because it leans on individual preparer vigilance, and vigilance is the first thing that erodes under staffing pressure.

What the AICPA's quality control framework requires of tax practices

The AICPA Tax Practice Quality Control Guide addresses quality control failures as a recurring factor in professional liability claims, with tax planning and compliance work representing a disproportionate share of that exposure.

The AICPA guide targets the firm-level system, covering far more than how one return gets reviewed. It covers leadership responsibility, human resources, engagement performance, and monitoring. Firms need written QC policies instead of habits passed down by word of mouth. They need engagement review responsibilities spelled out clearly: who reviews what, at which stage, with what gets left in writing afterward. They need a consultation process for gray-area or unusual positions, so judgment calls don't rest on one preparer's shoulders alone. And they need an actual monitoring function: periodic inspection of finished engagements to check whether the QC procedures are doing what they're supposed to do.

Monitoring is the piece most firms skip, or run once a year as a formality instead of a real check. Structurally it's the same idea as the IRS's Quality Assurance Review layer: checking whether the quality system itself works, not just whether one file came out clean. Firms often have all of this written down and still apply it inconsistently depending on engagement type. That inconsistency is a failure on its own, not a rounding error. There's a liability angle worth stating plainly here too: when a claim comes in, the question isn't only whether the return was wrong, but whether the firm had a documented process and actually followed it. The paper trail becomes the evidence.

How technology changes where and how QC checks can be embedded

Human-only review runs into a wall that good intentions can't fix: thoroughness tracks reviewer time, and reviewer time is the scarcest resource in a firm that's already short-staffed. Nobody's inventing more hours in a partner's day.

At intake, software can run document completeness checks against a checklist built for the specific engagement, flagging gaps before a preparer even opens the file. The same layer can compare against prior-year data to surface anomalies a rushed manual intake pass would miss, and it can handle multi-state nexus and filing obligation checks that would otherwise depend on whichever preparer happens to remember the rule for that particular state.

During preparation, software can cross-check entered figures against source documents as they're keyed in, flag positions that need technical review, and run jurisdiction-specific calculation checks for multi-state returns: exactly the category where the 2024 FDIC study found penalty rates 2.9 times higher for firms filing in five-plus states.

At sign-off, structured checklists force documentation of what was actually reviewed, which goes further than a signature claiming a review happened. Workflow routing enforces reviewer independence, so a preparer can't sign off on their own work. Deadline tracking with authorization gates keeps filings from going out before the right person clears them.

Marble is built around this exact gap. It automates the intake, document review, and compliance-check work that makes up the earlier QC layers, so the foundational checks are already done by the time a return reaches a human reviewer. Marble's workflow logic follows how tax engagements actually move through a firm, stage by stage, built around how tax work specifically operates rather than adapted from software meant for broader business operations. The goal isn't to replace a reviewer's judgment. It's to make sure that judgment gets spent on what actually needs it: complex positions, edge cases, client conversations, instead of re-checking whether a W-2 is missing.

Building a QC system that holds under real operating conditions

Quality control doesn't fail because practitioners stop caring. It fails because the system stacks all the pressure at the very end, at the exact moment a mistake is most expensive to catch and least likely to get caught.

A QC system that holds spreads accountability across every stage instead of parking it with one role. Quality control is a preparer's job, a manager's job, and a reviewer's job, all three at once; hand it to the reviewer alone and it degrades the moment volume rises, which it always does eventually. It also has to be procedural rather than improvised: written down, applied the same way across engagement types, checked periodically to confirm it's still working. That's the same principle behind the AICPA's monitoring requirement and the IRS's own QAR program.

Firms that build real checks at intake, real checks during preparation, and a sign-off stage that confirms rather than discovers are the firms whose error rates hold steady even when staffing thins and the workload doesn't let up. The rest will keep showing up in next year's penalty and restatement data. They'll call it bad luck again.

Venn diagram: Tax QC: Sign-Off vs. Early-Stage Controls. Compares Early-Stage QC and Sign-Off Review; overlap: Shared Controls.

Sources

  1. irs.gov
  2. irs.gov
  3. igentax.com

More in Compliance Workflows