CPAs frequently provide consulting or other nonattest services to clients for whom they also perform attest services. These engagements can add significant value, but they also require careful attention to independence. Under the AICPA Code of Professional Conduct, a CPA in public practice must be independent when the CPA or firm performs attest services, such as audits, reviews and agreed-upon procedures.
In Part 2 of this two-part series, learn about safeguards for reducing threats to independence, exceptions and applying the independence framework to consulting services. Check out Part 1, which looks at the independence rule and categories of independence threats.
Safeguards: Reducing Threats to an Acceptable Level
Safeguards may partially or completely eliminate a threat or diminish its potential influence. To be effective, safeguards should eliminate the threat or reduce it to an acceptable level. The Code identifies three broad categories of safeguards:
Safeguards created by the profession, legislation or regulation
Safeguards implemented by the client
Safeguards implemented by the firm
The effectiveness of a safeguard depends on the specific facts and circumstances, proper identification of threats, whether the safeguard is suitably designed, who is subject to it, how it is applied, the consistency of application, who applies it, how it interacts with other safeguards, and whether the client is a public interest entity.
Documentation Expectations
When a CPA applies safeguards to eliminate or reduce significant threats to an acceptable level, they should document the identified threats and safeguards applied. The failure to prepare the required documentation would be considered a violation of the Code.
Tip: For consulting engagements, documentation should therefore reflect the firm’s independence analysis. At a minimum, the analysis should identify the nature of the consulting service, the threats considered, the significance of those threats, the safeguards applied, and the basis for concluding that independence is not impaired.
Applying the Framework to Consulting Services
When a member performs consulting services for an attest client, self-review, management participation or advocacy threats may exist. If significant independence threats exist during the engagement or the period covered by the attest report, independence will be impaired unless those threats are reduced to an acceptable level and any requirements included in the nonattest-services interpretations have been met.
In practical terms, before accepting a consulting engagement for an attest client, the CPA should evaluate questions such as:
Will the consulting service cause the firm to review its own work during the attest engagement? This may create a self-review threat.
Will the firm assume management responsibilities? Taking on management’s role or responsibilities creates a management participation threat.
Will the firm promote the client’s interests or position? This may create an advocacy threat.
Will the engagement increase financial dependence on the client? Excessive reliance on consulting fees is a self-interest threat and a large proportion of fees from consulting services is an undue influence threat.
Are safeguards available and effective? Safeguards must eliminate the threat or reduce it to an acceptable level.
Should the analysis be documented? When safeguards are applied to significant threats, the identified threats and safeguards should be documented.
Considering the Cumulative Effect of Multiple Consulting and Nonattest Services
The independence analysis should not stop with each consulting or nonattest service considered separately. In fact, the Code requires the firm to consider the aggregate effect before agreeing to perform the services. Before agreeing to perform nonattest services, the CPA should evaluate whether multiple consulting and nonattest services performed by the CPA or the firm, in the aggregate, create a significant threat to independence that cannot be reduced to an acceptable level by safeguards.
This cumulative-effect analysis is important because several consulting and nonattest services that appear manageable individually may, in aggregate, create a more significant threat. For example, multiple consulting services may increase the risk of self-review, create greater familiarity with management’s processes, or increase the proportion of fees generated from nonattest services.
Period-of-Engagement Exception
The Code provides a limited circumstance in which independence would not be impaired even if the firm performed nonattest services that would otherwise have impaired independence during the period covered by the financial statements. This exception applies only if all of the following conditions exist:
The nonattest services were provided before the period of the engagement.
The nonattest services related to periods before the period covered by the financial statements.
The financial statements for the period to which the nonattest services relate were audited by another firm or, in the case of a review engagement, reviewed or audited by another firm.
Because all three conditions must exist, the exception should be applied carefully. If the consulting services occurred during the professional engagement period or related to the period covered by the financial statements, the exception may not be available under the excerpted guidance.
Practical Takeaway
Independence in consulting engagements requires more than concluding that a service won’t impact the attest service. When a firm provides consulting or other nonattest services to an attest client, it should evaluate whether the service creates threats to independence; determine whether those threats are significant; apply effective safeguards when available; consider the cumulative effect of multiple nonattest services; and document the threats and safeguards when safeguards are used to address significant threats.
The central question is whether a reasonable and informed third party, aware of the relevant information, would perceive that the CPA’s professional judgment is not compromised. If the answer is “yes” because threats are not significant or because effective safeguards reduce them to an acceptable level, then the CPA may conclude that independence is maintained under the Code. Otherwise, the CPA’s independence is impaired and the consulting or nonattest service should not be performed.
Jeremy Dillard, CPA, CGMA is Technical Standards Partner with SingerLewak.

