Quality Control vs. Quality Assurance in Tax Firms
Proactive system design catches recurring errors; reactive review catches only individual ones.

ISO 9000:2015 draws the line with precision most practitioners never bother to read. Quality assurance encompasses all planned and systematic activities implemented within a quality system to provide confidence that a product or service will meet its requirements. Quality control refers to the operational techniques and activities used to actually fulfill those requirements. QA is how a process is designed and governed. QC is inspection of what that process produces.
QA is proactive, present before work begins and persistent throughout the engagement. QC is reactive, operating on finished or near-finished output to detect deviations before they reach a client or a regulator. Neither replaces the other, because they aren't doing the same job.
The restaurant analogy survives scrutiny. A kitchen's food safety protocols, including temperature logs, supplier vetting, sanitation schedules, and staff training certifications, constitute QA. A chef tasting a dish before it leaves the pass constitutes QC. If the chef is talented and attentive, bad food rarely reaches the table. But if the walk-in cooler has been running warm for a week, no amount of tasting protects the diner. Inspection cannot compensate for a broken process upstream. Every professional services firm producing high-stakes documents under time pressure operates inside exactly that dynamic, whether or not it recognizes it.
How these two roles map onto what tax firms actually do
QC in a tax firm is engagement-level inspection: the preparer's checklist completed before a return leaves a desk, the manager's sign-off on a draft, the partner's review of a complex Schedule K-1 package. AICPA Tax Practice Quality Control guidance frames the purpose of tax return review as assuring accuracy and confirming that applicable tax law benefits have been properly applied. Output-focused, error-detection work. That is QC.
QA is different in kind, not merely in scope. It's the firm-level architecture that determines whether the conditions for error exist in the first place. It is client acceptance and continuance criteria that filter out engagements too complex for the firm's current capabilities, or clients whose records are chronically disorganized. It is hiring criteria defining what competencies a new staff member must demonstrate before touching a return. It is the CPE tracking system ensuring practitioners remain current on law changes. It is the engagement letter policy scoping work precisely enough that neither party misunderstands what is being delivered. And critically, it is leadership communicating, credibly and consistently, that quality matters as much as throughput. That last one doesn't appear on any checklist, but its absence shows up everywhere.
The AICPA TPQC framework's six elements map almost entirely onto the QA layer: tone at the top, independence, client acceptance and continuance, human resources, engagement performance, and monitoring. Most of those elements exist before a single return is opened. Engagement performance alone touches the work itself. The framework is, structurally, a QA document issued by a tax-focused body, and it's worth examining it that way.
The practitioner implication is direct. QC catches an error on a specific return. QA determines whether conditions exist for that error to keep recurring. A firm can have meticulous reviewers and no client acceptance criteria. It can have thorough checklists and no training standards. Both of those firms have QC. Neither has QA. They will keep producing the same errors, only faster.
The standards landscape that shapes how firms are expected to manage both layers
The standards environment for tax quality management is fragmented, and that fragmentation has direct operational consequences for every firm trying to build something coherent.
The AICPA's TPQC guidance, reissued in February 2020, provides the most comprehensive tax-specific quality management framework available, organized around those six elements. It's also a recommendation. Firms may adopt it in full, in part, or not at all without triggering an enforceable consequence from the AICPA. That is a significant limitation that the profession has not adequately reckoned with.
The Statements on Standards for Tax Services, revised effective January 1, 2024, added three new standards, including Section 1.4 on reliance on tools, which carries real weight as AI enters tax workflows and is enforceable for AICPA members. But the SSTSs govern practitioner conduct on individual engagements. They don't impose a firm-level quality management obligation. They reach QC more than QA.
The enforceable hook for QA at the firm level lives in Circular 230, Section 10.36, a provision added in 2011 that deserves far more attention in quality management conversations than it typically receives. It holds that responsible individuals at firms can face Office of Professional Responsibility sanctions, including censure, suspension, financial penalties, and loss of practice rights, for failing to maintain adequate compliance procedures. The IRS has stated plainly that firm-level process design is a professional obligation with consequences attached.
The AICPA issued SQMS 1 and SQMS 2 in 2022, effective December 15, 2025, for audit and attest engagements. Tax falls outside their scope, but their architecture is worth noting: they shift from a rules-based to a risk-based approach, requiring firms to assess their own risk environment and calibrate systems accordingly. Whether that philosophy eventually reaches tax-specific standards is an open question. The direction, however, is not.
Peer review rounds out the picture as an external QA check, required every three years for AICPA member firms and a statutory requirement across a majority of licensing jurisdictions. It examines a firm's quality control system from the outside. It doesn't substitute for internal monitoring, and it doesn't reach every engagement. It is a periodic signal, not a continuous safeguard.
The resulting gap is material. Quality management for tax work remains less codified and less consistently enforced than for audit, producing significant variation across firms in how either layer is built — or whether it's built at all.
What the error and liability data reveal about where quality breaks down
The data on tax errors and professional liability tell a coherent story, even read conservatively.
A 2024 Gartner survey found that 18% of accountants make financial errors at least daily, roughly a third make errors every week, and 59% admit to several errors per month. Those figures indicate QC is functioning imperfectly at best. Errors are reaching reviewers, some are being caught, but the volume suggests the upstream conditions generating those errors remain largely intact. Review is mitigating, not solving.
The IRS assessed over 50 million civil penalties totaling $84 billion in 2024. Not all of those trace to practitioner error. But the scale of downstream consequences from quality failures anywhere in the return preparation chain is not abstract.
Professional liability data are more direct. CNA Financial data covering a multi-year period shows that between 65% and 75% of CPA professional liability claims each year relate to tax services, with more than half of those involving improper tax treatment or advice. That claim profile points toward process-level failure. A reviewer who signs off on an incorrect basis calculation made an inspection error. A firm that accepted an estate planning engagement without requisite expertise, or failed to ensure its practitioners stayed current on relevant law, made a system error. The latter produces the former at scale, reliably.
Industry observation has also documented error rates spanning an extraordinarily wide range across firms. That spread is not statistical noise. It is evidence that firms without formal QA infrastructure perform differently in kind from those that have built it, not merely in degree.
One further signal from the audit side: withdrawn financial statements from public accounting errors reached a nine-year high in 2024. Audit and tax share staff, culture, and leadership at most CPA firms. A quality culture problem doesn't stay on one side of that wall.
Why firm size and the talent shortage make both layers harder to maintain
The structure of the profession makes this harder than it ought to be. Per a 2021 AICPA and CIMA estimate, the approximately 46,000 accounting firms in the United States include a vast majority with fewer than 20 employees. The typical tax firm is not a regional firm with a dedicated quality partner and a policies committee. It's a small business, often owner-operated, where the partner reviewing returns is simultaneously managing client relationships, supervising staff, and handling business development. Formal QA infrastructure doesn't compete with billable time in theory; it competes in practice, every day.
The talent shortage has made both layers harder to sustain simultaneously. The AICPA has reported that 75% of CPA firms face challenges hiring qualified staff. The Bureau of Labor Statistics projects more than 120,000 accounting and auditing job openings per year, while the CPA pipeline continues contracting, as documented in the 2025 AICPA and NASBA Trends Report. Supply and demand don't balance.
The QC risk from understaffing is visible. Overloaded reviewers compress review time, and compressed review time means more errors survive to filing. Industry observation suggests average review time runs approximately 40% of original preparation time, a ratio that becomes harder to maintain as headcount thins and return volume holds steady.
The QA risk is less visible but more consequential over time. When firms are in staffing survival mode, the activities that constitute QA — writing policies, running training, setting client acceptance criteria, monitoring whether procedures are followed — get deferred indefinitely. They're not billable. A missed deadline feels more urgent. They accumulate as institutional debt, quietly, until something goes wrong and the firm discovers it has no system to examine.
The AICPA's own guidance acknowledges that quality management is not one-size-fits-all. The appropriate scope of a firm's policies depends on firm size, office count, personnel experience levels, and the nature and complexity of the practice. Smaller firms aren't expected to replicate the infrastructure of a national firm. They're expected to build something proportionate. That distinction matters, because the alternative firms often choose is to build nothing.
How automation and AI fit into each layer — and where the distinction still holds
AI adoption in tax practice is accelerating at a pace that makes this conversation urgent rather than theoretical. Per the Thomson Reuters Institute's 2025 Generative AI in Professional Services Report, 21% of tax firms already use generative AI, 53% are planning or actively considering it, and the share with no plans dropped from 49% in 2024 to 25% in 2025. The direction is not ambiguous.
AI functions differently depending on which layer it's applied to, and whether a firm understands that distinction determines whether it deploys these tools deliberately or simply deploys them faster.
As a QC tool, AI handles automated return validation, document completeness flags, cross-return consistency checks, and anomaly detection that surfaces potential errors before a human reviewer opens the file. Inspection functions, executed more efficiently than manual review alone. Valuable, but limited to what QC has always been limited to: catching errors that have already been made.
As a QA enabler, AI operates at a different level, standardizing intake workflows, enforcing consistent data collection protocols before work begins, flagging client or engagement risk factors at the acceptance stage, ensuring that process standards are applied uniformly across staff with different experience levels. This is process-design work. It is harder to implement than automated review checks, and it requires a firm to have articulated its process standards clearly enough to encode them. Firms that haven't done that work find AI gives them nothing to systematize.
SSTS Section 1.4, effective January 1, 2024, makes the professional obligation explicit. A CPA may reasonably rely on tools in providing tax services, but use of a tool doesn't transfer professional responsibility to the software. The QA and QC obligations remain the practitioner's.
As of 2024, a significant majority of accounting departments have automated less than half of their work processes, meaning substantial runway remains for intentional deployment. Automating QC while leaving QA informal produces a faster path to the same systemic errors. Throughput increases. The liability profile does not improve.
Building a system that treats QA and QC as distinct but connected functions
The practical starting point is an audit of what already exists. Every activity a firm currently calls "quality" should be examined and categorized: does this activity prevent error conditions from arising, or does it catch errors in outputs? Most firms will find a functioning QC layer, however informal, and a thin or absent QA layer. That asymmetry is the problem to solve, and naming it accurately is where the work begins.
QA questions a firm should be able to answer affirmatively: Do written criteria exist for accepting or declining client engagements? Are training and CPE requirements defined, communicated, and tracked? Does leadership communicate quality expectations with the same regularity and emphasis as growth targets? Is there a mechanism to verify whether QC procedures are actually being followed, or does compliance depend entirely on individual judgment and the hope that no one's cutting corners under deadline pressure?
QC questions a firm should be able to answer affirmatively: Is there a documented, consistent review process for every return type the firm prepares? Are checklists used at each stage, and is their completion verifiable rather than assumed? Is there a second-reviewer threshold based on return complexity, dollar value, or engagement risk?
The AICPA TPQC's monitoring element is the connective tissue between these two layers. Internal monitoring doesn't inspect individual returns; it checks whether QC procedures are functioning as designed. It's how a firm learns whether its QA investments are producing the outcomes they were built to produce. Without monitoring, QA is a policy document filed somewhere and rarely consulted. With it, QA becomes a system that responds to evidence and improves over time.
The AICPA frames the goal as reasonable assurance of compliance with applicable statutory, regulatory, and professional requirements. Not certainty. A system that makes failure less likely and easier to detect when it does occur, calibrated to the firm's actual size and risk profile.
Firms that conflate QA and QC over-invest in review and under-invest in the conditions that make excessive review necessary. They hire more reviewers instead of asking why errors are reaching reviewers in the first place. They add checklist steps instead of asking whether the right client was accepted or whether the staff member understood the law they were applying. The firms that separate these two functions clearly, and build each one intentionally, stop solving the same problems on an annual cycle. That is the difference between a review process and a quality system.


