Quality Control Materials Description
All QCM Descriptions · Download PDF
Description of the Advantage Audit Non-public Company 2027 Audit Program
Technical review and independent QCM/QMM examination pending; automated checks do not establish conformity.
Provider: AuditFile, Inc.. Authors: AuditFile, Inc.. Designated technical reviewer: Gary Bong, CPA.
Quality control materials addressed by this Description DC1
Advantage Audit Non-public Company Audit Program, 2027 Edition
Formats and delivery methods
- The AuditFile web application delivers the program as a cloud engagement template. New engagements using this revision receive the listed planning, audit-area and completion categories, including the edition-specific Engagement Quality Review (EQR) checklist. The firm decides when an EQR is required.
- The AuditFile iOS application accesses engagement content. This Description does not assert that its presentation of guidance labels, citations or documentation fields is identical to the web application; delivery verification remains pending.
- The web application provides engagement exports and template exports. Template PDF and Excel exports contain procedure text, references, help and guidance labels, rather than evidence that procedures were performed. Excel template export includes the EQR only when selected. Engagement exports depend on the selected format and options; they should not be assumed to reproduce all notes, risk links, history, sign-offs or reasons for marking a procedure not applicable. User firms retain the complete engagement documentation.
- The Description is available in the web application and as a PDF. The program is not distributed as a printed manual. Editable practice-aid files supplied alongside it are identified separately below.
Definition of QCM DC5
Advantage Audit Non-public Company Audit Program, 2027 Edition are quality control materials (QCM). The AICPA defines QCM as materials (for example, manuals or tools), including industry- or subject matter-specific materials, intended to enable the operation of a firm's system of quality control and promote consistency in performing quality engagements. QCM may be made available through technology, for example, through automated tools and techniques, and IT applications. QCM address standards and interpretive guidance related to accounting; audit, attestation, review, compilation, or preparation engagements or other services that CPA firms may provide; or ethics, independence, quality control, quality management, peer review, or practice monitoring related to those services.
Other QCM providers DC2
AuditFile, Inc. authors and maintains the program content described here. The edition retains familiar organization from earlier editions and uses revised AuditFile procedure text. The professional standards linked from the program are third-party source material, identified separately below. The historical review of Wiley materials is not an examination of this edition.
Earlier editions descended from the Wiley Advantage Audit materials published by John Wiley & Sons, Inc. and authored by professionals of WithumSmith+Brown, PC. The historical May 7, 2018 AICPA review relates to the materials and scope identified in that report; it does not establish coverage of later AuditFile amendments or this 2027 edition. The current edition is maintained by AuditFile. John Wiley & Sons, Inc. and WithumSmith+Brown, PC did not author, review or endorse this edition. The familiar category organization is retained to support the AuditFile workflow.
Elements not addressed by this Description DC3
The following are provided alongside the program but are not quality control materials addressed by this Description. They are editable aids and reference material; user firms remain responsible for their suitability and content.
- Practice aids provided under the engagement's Practice Aids page, in the following groupings: Checklists (client acceptance and continuance, independence guide and nonattest independence guide, internal control checklist, GAAP disclosure checklist, PBC checklist sample); Audit Engagement Letter; Management Representation Letters (including the summary of uncorrected misstatements); Attorney's Letters; Cash In Banks; Marketable (and Nonmarketable) Securities; Notes Receivable; Accounts Receivable; Inventories; Prepaid Expenses; Deposits; Accounts Payable; Other Liabilities; Notes Payable and Long Term Debt; Stockholders' Equity; Audit Report (GAAP Financial Statements) illustrative reports; and AuditFile Sample Workpapers. These are editable templates and illustrations that user firms tailor; they are not QCM addressed by this Description.
- The GAAP disclosure checklist practice aid (2026 edition, prepared by AuditFile from the 2025 edition and updated for FASB Accounting Standards Updates through ASU 2026-03 that change presentation or disclosure for entities other than public business entities; the 2025 edition is retained for prior-year reference), which addresses FASB Accounting Standards Codification disclosure requirements; accounting standards are not the subject of this Description.
- The AU-C, AR-C, and other professional standards documents reproduced in the AuditFile reference library (linked from the citations in the program), which are the standards themselves, not QCM.
- AuditFile platform features that operate on the engagement but are not audit program content, including the trial balance import, financial statement builder, analytical review and sampling calculators, adjustments module, risk module, workpaper management, client portal, and all artificial intelligence assistance features (Chat CPA, agents, and document tools). Output of the AI features is not QCM and is not covered by this Description.
- Tutorial videos, help-center articles, sample engagements, and marketing materials.
Characteristics of the QCM DC6
Type and purpose
The program supports planning, performing and documenting an audit of a nonpublic commercial entity under U.S. GAAS within the firm's system of quality management. Its 56 categories follow the familiar sequence of client information, planning, audit areas and completion. Audit areas retain Basic Procedures, Further Procedures and Conclusion, financial classifications and leadsheets. Core procedures are in Basic Procedures; Further Procedures are tailored to assessed risks. Dedicated categories address risk assessment, engagement quality management, group audits, service organizations and EQR. Retaining the familiar organization does not cause an existing or rolled-forward engagement to receive updated procedures automatically.
The web program supports dated preparer and reviewer sign-offs, notes, workpaper links, procedure status and change history. Risk links are available through applicable risk-assessment procedures and the risk workflow. A user can mark a step not applicable; the user must document the reason in the notes or a linked workpaper because the status alone does not record that reason. Each procedure has either a standards reference or an explicit practice-guidance label. These features support documentation but do not by themselves satisfy AU-C 230; the firm must retain the evidence and conclusions supporting its work.
Topics addressed
- Engagement acceptance and continuance, ethical requirements and independence, and communication with a predecessor auditor (AU-C 210, AU-C 220, AICPA Code of Professional Conduct)
- Engagement-level quality management, including engagement partner responsibilities, resources, direction, supervision and review, consultation, engagement quality review, and documentation (AU-C 220, SQMS No. 2)
- Terms of the engagement and the engagement letter (AU-C 210)
- Planning, the overall audit strategy and audit plan, and responses to assessed risks (AU-C 300, AU-C 330)
- Understanding the entity and its environment, the applicable financial reporting framework, and the components of the entity's system of internal control, including IT (AU-C 315)
- Identifying and assessing the risks of material misstatement, including inherent risk factors, the spectrum of inherent risk, significant risks, control risk, the stand-back evaluation, and documentation (AU-C 315)
- Consideration of fraud, including the presumed risks in revenue recognition and management override, and the required responses (AU-C 240)
- Materiality, performance materiality, and the clearly trivial threshold (AU-C 320, AU-C 450)
- Analytical procedures used in planning, as substantive procedures, and in forming an overall conclusion (AU-C 520)
- External confirmations under currently effective AU-C 505, with separately labeled AuditFile practices for planning cash confirmations and evaluating confirmation services. SAS No. 150 is not early adopted in this revision.
- Group audits, including component auditors and referred-to auditors (AU-C 600)
- Entities using a service organization (AU-C 402)
- Substantive procedures for each material class of transactions, account balance, and disclosure, with relevant assertions identified for each step (AU-C 330)
- Audit evidence, information produced by the entity, external information sources, management's specialists, auditor's specialists, and third-party pricing information (AU-C 500, AU-C 501, AU-C 620)
- Auditing accounting estimates and related disclosures (AU-C 540)
- Related parties, laws and regulations, going concern, litigation, claims and assessments, and commitments and contingencies (AU-C 550, AU-C 250, AU-C 570, AU-C 501)
- Subsequent events and subsequently discovered facts (AU-C 560)
- Evaluation of misstatements and audit sampling (AU-C 450, AU-C 530)
- Written representations (AU-C 580)
- Communication with those charged with governance and of internal control related matters (AU-C 260, AU-C 265)
- Forming an opinion and the auditor's report, modified opinions, emphasis-of-matter and other-matter paragraphs, other information, and supplementary information (AU-C 700, 705, 706, 720, 725, 730)
- Audit documentation, file assembly, and retention (AU-C 230)
Clients for which the QCM are intended
| Area of practice | Nonpublic commercial (for-profit) entities whose financial statements are audited under U.S. GAAS; the program is not intended for issuers or for audits under PCAOB standards. |
|---|---|
| Industry | General commercial entities (wholesale and retail distribution, services, professional practices, technology, and similar businesses). Industry-specific characteristics (construction, manufacturing, real estate, restaurants, medical practices, investment entities, not-for-profit organizations, employee benefit plans, governmental entities, and common interest realty associations) are addressed by AuditFile's separate industry programs, not by this program. |
| Form or type of organization | Corporations (C corporations and S corporations), limited liability companies, partnerships, and sole proprietorships, whether owner-managed or with separate governance; the program includes steps for pass-through entity tax matters and owner-managed control environments. |
| Operational characteristics | Entities of any size that prepare general purpose financial statements under U.S. GAAP, typically with a single reporting entity and one or a small number of locations, a conventional accounting system (including cloud accounting software), and, where applicable, outsourced services such as payroll. The group audit section applies when the financial statements include the financial information of components; the service organization section applies when a service organization is part of the entity's information system. The program does not address special purpose frameworks, foreign financial reporting frameworks, or entities subject to governmental audit requirements. |
Engagements for which the QCM are intended
| Area of service | Audit of financial statements. |
|---|---|
| Level of service | An audit performed in accordance with auditing standards generally accepted in the United States of America, resulting in the expression of an opinion on general purpose financial statements prepared in accordance with U.S. GAAP. |
| Unique characteristics | The web workflow identifies requirements, application material, AuditFile practice guidance and generally accepted practice. Assertion links appear where relevant. Sign-offs, notes and workpaper links support documentation. Users record why procedures are not applicable and tailor conditional sections, including group audits, service organizations, initial audits and EQR, to the engagement. |
Other QCM intended to be used in conjunction with the program DC7
- The user firm's own system of quality management designed and implemented under SQMS No. 1, A Firm's System of Quality Management (QM section 10), including its policies for engagement quality reviews under SQMS No. 2. The program addresses engagement-level quality management under AU-C 220 and does not address firm-level quality management.
- AuditFile's SQMS 1 firm-level quality management program (a separate AuditFile product), which a user firm may use to design, document, and evaluate its system of quality management.
- The AICPA Professional Standards (AU-C sections) and the AICPA Code of Professional Conduct, which the program cites and which user firms must consult directly; the program is not a substitute for them.
Relevant standards and interpretive guidance addressed by the program DC8
Auditing Standards Board (ASB) of the AICPA
The program is designed for the AU-C standards applicable to calendar-2026 financial-statement audits, including the changes in SAS Nos. 145, 146, 147 and 149. Its section-level coverage matrix identifies addressed, partially addressed and excluded AU-C sections. Standards citations distinguish requirements and application material from provider-designed procedures. Named technical review of accuracy and completeness, including conformity with current amendments, remains pending. The program applies currently effective AU-C 505 and does not early adopt SAS No. 150. Exclusions and standards issued but not yet effective are described below.
AICPA Professional Ethics Executive Committee (AICPA Code of Professional Conduct)
The program addresses the AICPA Code of Professional Conduct as in effect on September 28, 2026, in the context of its application to an audit engagement: the Independence Rule (ET 1.200.001), the Nonattest Services subtopic (ET 1.295), and the Responding to Noncompliance With Laws and Regulations interpretation (ET 1.180.010). The Code is not reproduced; the user firm's independence and ethics policies and the Code itself govern.
AICPA Auditing Standards Board (Statements on Quality Management Standards)
The program addresses engagement-level AU-C 220 and includes an edition-specific EQR checklist organized around QM section 20 (SQMS No. 2). Firm-level design, implementation and operation of the system under QM section 10 remain outside this program. Review of the applicable amendments, including SQMS No. 3, is part of the final technical review; this Description does not claim that all SQMS requirements are contained in the engagement checklist.
Financial Accounting Standards Board (FASB)
The program is an auditing program; accounting standards are not its subject matter. Audit-area steps refer to FASB Accounting Standards Codification topics (for example, ASC 326, 330, 360, 450, 460, 606, 740, 842, 850, and 855) only to identify the accounting and disclosure matters the auditor evaluates, and those references reflect the Codification as of September 28, 2026. Accounting standards with disclosure requirements are addressed by the GAAP disclosure checklist practice aid, which is outside this Description.
Standards issued and effective but not addressed or not fully addressed DC9
| Standard | Status | Why | How the program treats it |
|---|---|---|---|
| AU-C 610, Using the Work of Internal Auditors | partially addressed | An internal audit function is uncommon in nonpublic commercial entities. | The program requires the auditor to determine whether an internal audit function exists and to apply AU-C 610 directly when it does; the requirements for using internal auditors' work or direct assistance are not reproduced. |
| AU-C 701, Communicating Key Audit Matters in the Independent Auditor's Report | not addressed | Key audit matters are communicated only when the auditor is engaged to do so, which is not part of a standard audit of a nonpublic commercial entity. | The reporting category directs the auditor to apply AU-C 701 directly if so engaged; an illustrative report including key audit matters is a practice aid outside the QCM. |
| AU-C 800, 805, 806, and 810 (special purpose frameworks; single statements and specific elements; reporting on contractual or regulatory compliance; summary financial statements) | not addressed | The program is designed for audits of a complete set of general purpose financial statements prepared in accordance with U.S. GAAP; these sections apply to other engagements or frameworks. | Not reproduced; user firms must tailor the program and apply the sections directly when applicable. |
| AU-C 905, 910, 915, 920, 925, 930, 940, and 945 (restricted-use alerts; other-country frameworks; reports on application of requirements; letters for underwriters; SEC filings; interim financial information; integrated audits of internal control; exempt offering documents) | not addressed | These sections apply to engagements, circumstances, or reporting responsibilities outside a GAAS audit of a nonpublic commercial entity's annual financial statements. | Not reproduced; the AU-C 265 communication includes the restriction on use that section requires. |
| AU-C 935, Compliance Audits | not addressed | Compliance audits are separate engagements performed under governmental audit requirements and are addressed by AuditFile's Governmental and Single Audit programs. | Not reproduced. |
Standards issued but not yet effective DC10
The user applying the program must evaluate each standard's applicability and effective date based on the period covered by each specific engagement.
| Standard | Effective date | Addressed by the program? | Early implementation |
|---|---|---|---|
| SAS No. 146, Quality Management for an Engagement Conducted in Accordance With Generally Accepted Auditing Standards (AU-C 220) | Engagements conducted in accordance with GAAS for periods beginning on or after December 15, 2025 (effective for calendar-2026 year-ends; not yet effective for earlier fiscal years that may use this edition). | Addressed in the Engagement Quality Management category and the Engagement Quality Review checklist, with the extant AU-C 220 requirements replaced. | Early implementation is permitted; SAS No. 146 does not prohibit early implementation (AU-C 220.10 states the effective date; the AICPA expects implementation concurrently with SQMS No. 1). |
| SAS No. 149, Special Considerations — Audits of Group Financial Statements (Including the Work of Component Auditors and Audits of Referred-to Auditors) (AU-C 600) | Audits of group financial statements for periods ending on or after December 15, 2026. | Addressed in the Group Audits category, with the extant AU-C 600 requirements replaced; the category is completed only when the financial statements are group financial statements. | Early implementation is permitted; SAS No. 149 does not prohibit early implementation (AU-C 600.14 states the effective date). |
| SAS No. 150, External Confirmations (amending AU-C 505 and AU-C 330) | Audits of financial statements for periods ending on or after December 15, 2028; issued July 2026. | Not early adopted in this revision. Confirmation steps follow currently effective AU-C 505. Cash-confirmation planning and confirmation-service evaluation are labeled AuditFile practice guidance. A firm electing early implementation must apply the complete final standard and supplement the program for all amendments; those practices alone do not constitute implementation. | Early implementation is permitted. This edition does not make that election for the user firm. |
| SAS No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements (approved, publication pending at the Description date) | Audits of financial statements for periods ending on or after December 15, 2028 (approved by the ASB on August 20, 2026; publication of the final standard expected October 2026). | Not incorporated. The Fraud category follows currently effective AU-C 240. Monitor final publication and evaluate all changes before claiming implementation. | Early implementation is permitted (to be verified against the final standard when published). |
| SQMS No. 1, A Firm's System of Quality Management; SQMS No. 2, Engagement Quality Reviews; SQMS No. 3, Amendments to QM Sections 10 and 20 | Systems of quality management designed and implemented by December 15, 2025, with an evaluation of the system within one year of that date; SQMS No. 2 applies to engagements for periods beginning on or after December 15, 2025. | Engagement-level aspects are addressed through AU-C 220 and the Engagement Quality Review checklist; firm-level requirements are not addressed by this program. | Early implementation is permitted. |
Policy for updating the QCM content DC11
AuditFile updates the Non-public Company program annually and provides interim corrections and standards updates when needed. Each revision should have an updated Description date, content digest and change record. Technical approval must identify the exact approved revision.
Updates apply to newly created engagements. Existing engagements retain their imported and tailored content; rolling forward an engagement retains that content rather than installing the latest program. The firm must compare its engagement with the applicable revision and incorporate necessary changes. The About page identifies the current Description for the program edition, not an immutable snapshot of the procedures in a tailored or rolled-forward engagement.
User firm responsibilities DC12
User firms are responsible for the following:
- Determining whether the QCM are suitable for the user firm's purposes
- Understanding that the QCM are not intended to be a substitute for the standards and interpretive guidance, an evaluation thereof, or professional judgment
- Using the most up-to-date QCM available that are applicable in the circumstances, including accessing and using the most recent and effective relevant standards and interpretive guidance that are not addressed or not fully addressed by the QCM
- Properly implementing the QCM and using professional judgment in the application of the QCM based on the facts and circumstances (for example, of each engagement)
- Providing the appropriate training for the use of the QCM and performing the appropriate supervision and review procedures regarding the use of the QCM based on the skill, training, knowledge, and experience of individual users within the user firm
- Identifying that there may be certain facts, circumstances, risk factors, or specific issues that exist for a particular client, engagement, or user firm that may not be addressed by the QCM; in that case, understanding that the QCM will require tailoring and augmentation to address such facts, circumstances, risk factors, or specific issues
- Monitoring the activities of standard-setting bodies for changes that would affect the user firm, including amendments of standards and interpretive guidance and deferrals of effective dates
- Complying with relevant professional standards and interpretive guidance
- Understanding that the effectiveness of the QCM is dependent on the user firm fulfilling the preceding responsibilities and the effectiveness of its actions
Attachment: changes from the prior edition
- The 2026 category names, audit-area sequence, Basic Procedures / Further Procedures / Conclusion sections, financial classifications and leadsheets are retained. The 2027 procedure text is revised and streamlined. Core audit-area tests are in Basic Procedures so risk-tailored visibility does not hide the normal audit work.
- The program adds detailed risk assessment, engagement quality management, service-organization and group-audit coverage. The group-audit model distinguishes component auditors and referred-to auditors. These changes remain subject to final technical review.
- Every procedure carries a content-type label. Provider-designed tests are labeled AuditFile practice guidance, with useful underlying standards in help; a standards citation is not used to imply that every detailed testing method is mandatory.
- An edition-specific, cited and labeled EQR replaces reliance on the shared legacy add-in for this program. It covers reviewer eligibility, significant judgments, completion and documentation when an EQR is required.
- Audit sampling now addresses design, sample size, selection, untestable items, exceptions, projection and sampling risk. File-assembly wording distinguishes removing superseded drafts during assembly from prohibited deletion after final assembly.
- Confirmation procedures use currently effective AU-C 505. This revision removes the unsupported claim of full early implementation of SAS No. 150.
- Automated validation checks references, labels, application-dependent names, financial metadata, coverage mappings and the Description digest. Technical sign-off, review evidence, delivery verification and the agreed examination criteria remain separate recorded review steps.
- The linked GAAP disclosure checklist and other practice aids are separate companion materials excluded from this Description; their provision does not establish coverage by an examination of this program.
How to read the program
Every category, audit section and step in the program carries a reference to the professional standard it reproduces or derives from, and every step is labeled with one of the following content types:
- Requirement Reproduces or derives from a requirement of the cited standard.
- Application material Reflects the application and other explanatory material of the cited standard.
- AuditFile practice guidance AuditFile's practice guidance: a workflow or documentation step that is not itself a requirement of a professional standard.
- Generally accepted practice Based on widely recognized or generally accepted practice rather than on a requirement of a professional standard.