Est.

Software That Enforces Role-Based QA and QC Separation Across Tax Engagement Workflows

AICPA compliance now requires software-enforced separation between tax preparers and reviewers.

Contributing Writer · · 11 min read
Cover illustration for “Software That Enforces Role-Based QA and QC Separation Across Tax Engagement Workflows”
Compliance Operations · October 9, 2026 · 11 min read · 2,447 words

Tax firms have until December 15, 2026, to complete an evaluation of their system of quality management under the AICPA's new Statements on Quality Management Standards. That deadline turns software-enforced role separation between preparers and reviewers from a workflow convenience into a documented compliance obligation. Software that enforces this separation works by routing engagements through predefined approval hierarchies so the preparer and reviewer are never the same person, and by generating the audit trail that proves it. Firms evaluating tax engagement software now need to understand what these enforcement mechanisms look like in practice, because "someone reviewed it" no longer satisfies the standard; the structure of review itself has to be demonstrable on request.

QA/QC separation in tax engagements as a compliance obligation

The AICPA's Statements on Quality Management Standards took effect December 15, 2025, and they rebuilt the quality control framework for CPA firms from the ground up, moving it from a rules-based checklist to a risk-based system that firms must design, implement, and then prove works. SQMS 2 is the piece of that framework that speaks directly to review structure. It defines the role of the engagement quality reviewer in detail, covering objectivity and eligibility criteria, competence standards, and documentation obligations, and it states that this reviewer cannot be a member of the engagement team. That single requirement is the regulatory anchor for everything that follows: a firm cannot satisfy SQMS 2 by having the preparer sign off on their own work, however informally that might have passed muster under the old rules-based regime.

The December 2026 evaluation deadline is not a distant planning horizon. Firms are required to assess whether their system of quality management actually functions. Any firm that has not already operationalized role separation is working against a closing window, not a future one. Circular 230 and the AICPA Standards for Tax Services add independent pressure on top of SQMS: both require diligence and documentation that a generic task list or shared spreadsheet cannot reliably produce, and record retention obligations flow separately through the AICPA Code of Professional Conduct. None of these regulatory sources is new in isolation. What has changed is that they now converge on a single operational demand: firms must be able to show, for any given engagement, that the person who prepared the return was not the person who cleared it, and that the clearing decision is documented well enough to survive scrutiny.

QA and QC separation inside a tax engagement workflow

QA/QC separation in a tax practice means that the individual who prepares a return is structurally prevented from being the same individual who approves it for filing, and that each role carries its own documented scope of responsibility inside a defined approval chain. The structure underneath it involves several possible tiers: junior staff who do first-pass preparation, senior accountants who refine the work, managers who review for completeness and technical accuracy, compliance officers who check for firm-level risk, and, where SQMS 2 applies, an engagement quality reviewer who sits outside the engagement team. Each tier has scoped authority over a specific stage, and none of those tiers can substitute for another.

The engagement quality reviewer deserves particular attention because the role is easy to misunderstand. Under SQMS 2, this person does not redo the engagement team's work. Instead, the reviewer performs an objective evaluation of the significant judgments the engagement team made and the conclusions they reached. That is a fundamentally different function from double-checking arithmetic or confirming a form was filled out correctly, and it cannot be collapsed into the preparer's job no matter how experienced that preparer is.

Even outside the formal engagement quality review context, a functioning advisory workflow needs at least four distinct role categories to operate soundly: a relationship owner who manages the client, a technical owner who handles the substantive tax work, a reviewer who checks it, and an implementation owner who executes whatever the engagement produces. Small firms often cannot staff four separate people into four separate roles, and one person may legitimately hold more than one of these functions. The roles still have to be named and visible on a per-engagement basis, because an unnamed role is an unenforceable one.

This framework maps onto a useful software distinction. QA, the system of standards and oversight that establishes whether the process itself is sound, is enforced through system-level permissions and workflow design. QC, the per-engagement checks that confirm a specific return is correct, is enforced through per-return gates, checklists, and sign-off requirements. Platforms built specifically for tax practitioners, Marble among them, can embed QC checkpoints directly into the engagement workflow, attaching compliance-validated guidance and regulatory citations to each review stage so a reviewer starts from a documented basis rather than from a blank screen and institutional memory.

The three layered mechanisms by which software enforces role separation

Diagram: Three Mechanisms That Make Role Separation Enforceable. Visualizes: Visualize three interdependent enforcement layers that software must provide for QA/QC separation to be real rather than nominal: (1) Role-Based Permissions — controls who…

Software enforces QA/QC separation through three mechanisms that depend on one another: role-based permissions, workflow stage gates, and immutable audit trails. A platform strong in one of these and weak in another does not deliver real enforcement, only the appearance of it.

Role-based permissions are the foundation. A platform needs the ability to limit access by role, by office, or by team, and to restrict sensitive information to the people who actually need it. Not every team member needs visibility into billing, and not every case manager needs administrative access to the system. If the platform cannot control who sees what, it cannot control who is authorized to act on what, and the preparer/reviewer separation goes unenforced at the permission layer even when the workflow nominally routes work from one person to another.

Workflow stage gates make "done" a meaningful, checkable state that can be verified. A gate blocks a return from moving to the next stage until a required action has actually happened: a document uploaded, a checklist completed, an explicit sign-off recorded by the person authorized to give it. Workflow tools that lack evidence-based review steps and exception routing may speed up the process without making it any more reliable, because speed and substance are not the same achievement. Gates also need to route exceptions back to the preparer for resolution rather than letting a reviewer silently override a flagged item, since a silent override breaks the trail's accuracy about what actually happened on the engagement.

Immutable audit trails are the third layer, and they convert the workflow from a sequence of steps into an accountable system. The trail records who did what and when, with notes, uploads, and messages time-stamped and tied to the specific case, replacing reliance on someone's memory of events. This is the documentation SQMS requires for the system of quality management evaluation, and it is the record a firm would need to produce in response to any post-engagement inquiry. Tax-specific platforms that maintain searchable engagement context and documentation history make it possible to reconstruct the full decision chain for a regulator, something generic task management software typically cannot do because it logs the action taken without capturing the reasoning behind it.

A gate with no audit trail behind it cannot prove compliance happened. An audit trail sitting behind a gate anyone can bypass does not prove the compliance it records happened. The three mechanisms have to function as a set.

How leading platforms implement these mechanisms in practice

Platforms that address role-based QA/QC enforcement make meaningfully different design choices in workflow architecture, AI integration, and what each considers a "reviewable" artifact, and those differences matter when matching software to a firm's actual structure.

CCH Axcess Tax lets firms build their own workflow configurations. A senior accountant at Ryan & Wetmore has described the ability to create workflow that sets up stages of the return and routes it to the responsible staff, confirming that the stage logic is practitioner-configured. That flexibility is also its limit: CCH Axcess can calculate, import, share, diagnose, track, sign, and transmit, but whether the client's underlying facts are complete, whether a workpaper actually proves the result it claims, and whether an automated classification was the appropriate one to apply are judgment calls it cannot make. Those judgment calls remain with the humans the workflow routes work to.

Thomson Reuters launched Ready to Review on December 15, 2025, a cloud-based agentic AI tax workflow application built on the CoCounsel Tax, Audit and Accounting platform. It is designed to modernize 1040 preparation by using AI agents to process source documents and prior-year returns, extract and categorize data, and produce returns ready for professional review. The structural separation is built into the architecture itself: the Tax Preparer Agent receives verified data from the Gather Agent and produces a complete draft return ready for the professional's review, so the AI agent occupies the preparer role and the human professional occupies the reviewer role. The platform also autonomously creates and resolves routine diagnostics and categorizes issues by priority, operationalizing the SQMS idea of reserving reviewer attention for matters that involve significant judgment over routine mechanics.

Drake Workflow, launched September 16, 2025, takes a different approach by tying together Drake Tax, Drake Portals, Drake E-Sign, Drake Pay, and Drake Tax Online so that work moves across people and products without manual handoffs through a separate spreadsheet. Return status updates automatically as work completes inside Drake's tools, and tasks route based on that status with built-in flags for items needing attention. The automation here is status-driven rather than AI-agent-driven, a different mechanism than Ready to Review's but one aimed at the same goal of keeping work moving through defined stages without relying on someone remembering to hand it off.

Intuit Lacerte supports multi-user environments with role-based permissions and audit trails and is commonly used for high-complexity returns requiring multi-step review, with diagnostics, proforma, and reviewer workflows built into the product. IRSLogics takes a rules-and-workflow-engine approach, letting firms build automations that reflect their own internal control policies, with implementation guidance that recommends aligning those workflows to the firm's existing quality control manual and reflecting partner, manager, and staff responsibilities directly in the permission structure. It is positioned explicitly for resolution and representation work alongside compliance, which matters for firms where tax resolution staff and return preparation staff share roles and client records. IRIS Practice Management and Jetpack Workflow round out the category, with Jetpack Workflow requiring deliberate configuration of tasks, stages, and roles to match a firm's internal standards, a tradeoff that fits practices with consistent enough intake volume to justify the setup.

Marble takes a purpose-built approach instead of retrofitting general accounting software for tax use, automating the routine backend of an engagement, intake, document review, compliance checks, so that practitioner time concentrates on review, exceptions, client judgment, and final approval over production labor. The underlying design philosophy tracks the SQMS-era quality management model closely: route preparation work through structured automation, keep the human professional anchored in the reviewer and advisory role, and generate the audit trail that proves the separation happened.

Where software enforcement reaches its limit

Software can enforce who signs a workpaper and when. It cannot enforce that the person signing actually exercised independent judgment in doing so, and mistaking structural compliance for substantive review is the most dangerous failure mode a firm can fall into under an SQMS-governed quality system. A fully configured workflow platform can calculate, import, share, diagnose, track, sign, and transmit documents across every stage of an engagement. It cannot judge whether the client's facts are complete, whether a workpaper actually proves the result it reports, whether an automated classification was the right one to apply, whether a state tax treatment is supportable, or whether the file surfaces to the reviewer what requires their judgment and what does not.

SQMS 2 reflects this limit directly in how it defines the engagement quality reviewer's job: that person does not reperform the engagement team's procedures but exercises independent judgment about whether the team's significant judgments were appropriate. That is a human cognitive act, and no workflow gate, however well configured, can substitute for it. Most platforms can answer a first-level checklist question, whether the firm can require a review before anything goes to the client, reasonably well. Fewer handle the next two questions as cleanly: can a reviewer see the source documents and underlying assumptions in one place, and can internal review notes stay separated from anything client-facing. A configured workflow becomes a genuinely reviewable one only when those two questions are answered.

The practical response is not to look for a platform that somehow manufactures a second person, but to build alternate controls into the practice, checklists, automated alerts, and scheduled self-review points that monitor the work even without a structurally separate reviewer, as a clarification of what this category of software can do. Every platform in this space enforces structure; none of them enforces judgment.

How AI-assisted preparation changes the preparer/reviewer relationship

Thomson Reuters' Ready to Review illustrates a structural question the rest of the industry will need to answer soon: when an AI agent performs the preparation function, the human "preparer" role effectively collapses into the reviewer role, and it remains unresolved whether SQMS 2's reviewer independence requirements were written with that collapse in mind. The Tax Preparer Agent produces the draft return. The human professional who once prepared returns is now reviewing what the agent produced, which is a different cognitive task than preparing one, even though the job title on the organizational chart may not have changed.

This is not a distant hypothetical. Thomson Reuters' 2026 State of Tax Professionals Report found that only 11% of firms report using no automation at all, down from 18% in 2025, a pace of adoption that shows the shift away from fully manual preparation is already well underway across the profession, including firms beyond early adopters experimenting at the margins.

What happens to the two-person separation that SQMS 2 was built to protect becomes the substantive issue. If an AI agent is functioning as the de facto preparer, the traditional structure, preparer and reviewer as two different humans, stays intact on paper but stops doing the work it was designed to do. The human who once prepared the return is now reviewing AI output instead. The human designated as the engagement quality reviewer is, in effect, reviewing that same person's review of AI output. There is no independent preparer left in the chain for the reviewer's independence to be independent from. Firms adopting agentic tax preparation tools will need to reason through what engagement quality review means when the artifact under review was never produced by a human preparer in the first place, and the standards governing that question have not yet caught up to the tools already on the market.

Sources

  1. Tax workflow for accounting firms: Best practices & automation tips
  2. What to know about engagement quality reviews (SQMS No. 2)
  3. Role Based Access Control (RBAC): 2026 Guide
  4. How AI-native tax preparation changes who does the work
  5. What to know about the new quality management standards

More in Compliance Operations