Quality Control Materials Description

All QCM Descriptions · Download PDF

Description of the Advantage Audit Non-public Company 2027 Audit Program

Citations cross-checked against the AICPA Professional Standards codification text (AU-C sections) on 2026-09-28; QCM examination by an independent CPA firm pending

Description, as of 2026-09-28 , of Advantage Audit Non-public Company Audit Program, 2027 Edition (edition released 2026-09-28)
Provider: AuditFile, Inc.. Authors: AuditFile, Inc.. Technical review: Gary Bong, CPA.

Quality control materials addressed by this Description DC1

Advantage Audit Non-public Company Audit Program, 2027 Edition

Formats and delivery methods

  • The AuditFile web application (auditfile.com), a cloud-hosted software-as-a-service platform in which the program is delivered as an engagement template. A new engagement created from the "Non-public Company 2027" program receives the complete program (planning documents, audit program sections, and completion checklists) together with the Engagement Quality Review checklist that AuditFile adds to every Advantage Audit audit engagement.
  • The AuditFile iOS application, which presents the same engagement content (sections, steps, citations, and sign-offs) for engagements created in the web application.
  • Exports of the engagement program from the web application to PDF, Microsoft Word, and Microsoft Excel, which reproduce the steps, citations, content-type labels, sign-offs, and not-applicable rationale.
  • The program is not distributed in print or as a standalone file; it is not provided through any other delivery method.

Definition of QCM DC5

Advantage Audit Non-public Company Audit Program, 2027 Edition are quality control materials (QCM). The AICPA defines QCM as materials (for example, manuals or tools), including industry- or subject matter-specific materials, intended to enable the operation of a firm's system of quality control and promote consistency in performing quality engagements. QCM may be made available through technology, for example, through automated tools and techniques, and IT applications. QCM address standards and interpretive guidance related to accounting; audit, attestation, review, compilation, or preparation engagements or other services that CPA firms may provide; or ethics, independence, quality control, quality management, peer review, or practice monitoring related to those services.

Other QCM providers DC2

The elements of the QCM within this Description are authored and maintained by AuditFile, Inc. and no other QCM provider. The 2027 edition is a complete rewrite of AuditFile's Non-Public Company audit program prepared from the current AICPA codification; no content of the 2027 edition is reproduced from another provider's quality control materials.

Editions of the Non-Public Company program through 2026 descended from the "Wiley Advantage Audit" audit programs published by John Wiley & Sons, Inc. and authored by professionals of WithumSmith+Brown, PC; those editions were covered by the AICPA quality control materials review of the Wiley Advantage Audit materials reported on May 7, 2018, a review type the AICPA discontinued in May 2022. The 2027 edition was written by AuditFile, Inc. from the AICPA codification and does not reproduce that content; John Wiley & Sons, Inc. and WithumSmith+Brown, PC did not author, review, or endorse the 2027 edition. "Advantage Audit" is the name of AuditFile's audit program product line; "Wiley" is a trademark of John Wiley & Sons, Inc. and is used only to identify the origin of earlier editions.

Elements not addressed by this Description DC3

The following are provided alongside the program but are not quality control materials addressed by this Description. They are editable aids and reference material; user firms remain responsible for their suitability and content.

  • Practice aids provided under the engagement's Practice Aids page, in the following groupings: Checklists (client acceptance and continuance, independence guide and nonattest independence guide, internal control checklist, GAAP disclosure checklist, PBC checklist sample); Audit Engagement Letter; Management Representation Letters (including the summary of uncorrected misstatements); Attorney's Letters; Cash In Banks; Marketable (and Nonmarketable) Securities; Notes Receivable; Accounts Receivable; Inventories; Prepaid Expenses; Deposits; Accounts Payable; Other Liabilities; Notes Payable and Long Term Debt; Stockholders' Equity; Audit Report (GAAP Financial Statements) illustrative reports; and AuditFile Sample Workpapers. These are editable templates and illustrations that user firms tailor; they are not QCM addressed by this Description.
  • The GAAP disclosure checklist practice aid (2026 edition, prepared by AuditFile from the 2025 edition and updated for FASB Accounting Standards Updates through ASU 2026-03 that change presentation or disclosure for entities other than public business entities; the 2025 edition is retained for prior-year reference), which addresses FASB Accounting Standards Codification disclosure requirements; accounting standards are not the subject of this Description.
  • The AU-C, AR-C, and other professional standards documents reproduced in the AuditFile reference library (linked from the citations in the program), which are the standards themselves, not QCM.
  • AuditFile platform features that operate on the engagement but are not audit program content, including the trial balance import, financial statement builder, analytical review and sampling calculators, adjustments module, risk module, workpaper management, client portal, and all artificial intelligence assistance features (Chat CPA, agents, and document tools). Output of the AI features is not QCM and is not covered by this Description.
  • The Engagement Quality Review (EQR) checklist is added to every Advantage Audit audit engagement at creation and is treated as part of the program content for the purposes of this Description; the firm's determination of whether an engagement quality review is required remains a firm-level policy matter under SQMS No. 1.
  • Tutorial videos, help-center articles, sample engagements, and marketing materials.

Characteristics of the QCM DC6

Type and purpose

The program is a set of planning documents, audit programs, and completion checklists intended to enable a user firm to plan, perform, and document an audit of the financial statements of a nonpublic commercial entity in accordance with auditing standards generally accepted in the United States of America (U.S. GAAS), within the firm's system of quality management. It is organized as 55 categories that keep the category structure of the prior editions so that engagements roll forward and the AuditFile planning tools (Overall Strategy and Plan, Ratio Analysis, Confirmation Tracker, Disclosure Checklist, leadsheets) continue to operate: client information (Trial Balance, Adjustments, Financial Statements); planning (New Client, Engagement Letter, Continuation, Engagement Quality Management, Permanent File, Prior Year Statements, Prior Year Tax Returns, Budget, Brainstorming, Entity / Environment, Internal Control Environment, Internal Control Cycles, Identifying and Assessing the Risks of Material Misstatement, Other Planning, Fraud, Materiality, Overall Strategy and Plan, Journal Entry Testing, Ratio Analysis, Preliminary Analytical Review, Confirmation Tracker, Group Audits (SAS 149), Service Organizations); the audit program by area, each with Basic Procedures, Further Procedures, and Conclusion sections (Cash, Investments, Accounts Receivable, Inventory, PPE, Other Assets, Accounts Payable, Accrued Liabilities, Income Taxes, Debt, Equity, Revenue, Expense); and completion (Related Party, Subsequent Events, Estimates, Noncompliance with Laws and Regulations, Going Concern, Consultation, Commitments, Final Analytical Review, Legal Letter, Representation Letter, Disclosure Checklist, Communication, Concluding Activities, Conclusion, Financial Statements Issued, Audit Documentation Checklist).

The program provides a means to document the performance of the audit procedures and the conclusions reached: each step carries preparer and reviewer sign-offs with dates, a not-applicable option with rationale, links to workpapers and risks, notes, and change history, and each category and step cites the professional standard it reproduces or derives from. The program is not by itself the complete audit documentation required by AU-C 230; user firms remain responsible for the workpapers, memoranda, and other documentation that support the procedures.

Topics addressed

  • Engagement acceptance and continuance, ethical requirements and independence, and communication with a predecessor auditor (AU-C 210, AU-C 220, AICPA Code of Professional Conduct)
  • Engagement-level quality management, including engagement partner responsibilities, resources, direction, supervision and review, consultation, engagement quality review, and documentation (AU-C 220, SQMS No. 2)
  • Terms of the engagement and the engagement letter (AU-C 210)
  • Planning, the overall audit strategy and audit plan, and responses to assessed risks (AU-C 300, AU-C 330)
  • Understanding the entity and its environment, the applicable financial reporting framework, and the components of the entity's system of internal control, including IT (AU-C 315)
  • Identifying and assessing the risks of material misstatement, including inherent risk factors, the spectrum of inherent risk, significant risks, control risk, the stand-back evaluation, and documentation (AU-C 315)
  • Consideration of fraud, including the presumed risks in revenue recognition and management override, and the required responses (AU-C 240)
  • Materiality, performance materiality, and the clearly trivial threshold (AU-C 320, AU-C 450)
  • Analytical procedures used in planning, as substantive procedures, and in forming an overall conclusion (AU-C 520)
  • External confirmations, including cash confirmations, intermediaries, and negative confirmations (AU-C 505, SAS No. 150 on an early-implementation basis)
  • Group audits, including component auditors and referred-to auditors (AU-C 600)
  • Entities using a service organization (AU-C 402)
  • Substantive procedures for each material class of transactions, account balance, and disclosure, with relevant assertions identified for each step (AU-C 330)
  • Audit evidence, information produced by the entity, external information sources, management's specialists, auditor's specialists, and third-party pricing information (AU-C 500, AU-C 501, AU-C 620)
  • Auditing accounting estimates and related disclosures (AU-C 540)
  • Related parties, laws and regulations, going concern, litigation, claims and assessments, and commitments and contingencies (AU-C 550, AU-C 250, AU-C 570, AU-C 501)
  • Subsequent events and subsequently discovered facts (AU-C 560)
  • Evaluation of misstatements and audit sampling (AU-C 450, AU-C 530)
  • Written representations (AU-C 580)
  • Communication with those charged with governance and of internal control related matters (AU-C 260, AU-C 265)
  • Forming an opinion and the auditor's report, modified opinions, emphasis-of-matter and other-matter paragraphs, other information, and supplementary information (AU-C 700, 705, 706, 720, 725, 730)
  • Audit documentation, file assembly, and retention (AU-C 230)

Clients for which the QCM are intended

Area of practice Nonpublic commercial (for-profit) entities whose financial statements are audited under U.S. GAAS; the program is not intended for issuers or for audits under PCAOB standards.
Industry General commercial entities (wholesale and retail distribution, services, professional practices, technology, and similar businesses). Industry-specific characteristics (construction, manufacturing, real estate, restaurants, medical practices, investment entities, not-for-profit organizations, employee benefit plans, governmental entities, and common interest realty associations) are addressed by AuditFile's separate industry programs, not by this program.
Form or type of organization Corporations (C corporations and S corporations), limited liability companies, partnerships, and sole proprietorships, whether owner-managed or with separate governance; the program includes steps for pass-through entity tax matters and owner-managed control environments.
Operational characteristics Entities of any size that prepare general purpose financial statements under U.S. GAAP, typically with a single reporting entity and one or a small number of locations, a conventional accounting system (including cloud accounting software), and, where applicable, outsourced services such as payroll. The group audit section applies when the financial statements include the financial information of components; the service organization section applies when a service organization is part of the entity's information system. The program does not address special purpose frameworks, foreign financial reporting frameworks, or entities subject to governmental audit requirements.

Engagements for which the QCM are intended

Area of service Audit of financial statements.
Level of service An audit performed in accordance with auditing standards generally accepted in the United States of America, resulting in the expression of an opinion on general purpose financial statements prepared in accordance with U.S. GAAP.
Unique characteristics The program is delivered in a cloud workflow: each step carries its standards citation, a content-type label (requirement, application material, AuditFile practice guidance, or generally accepted practice), the relevant assertions, preparer and reviewer sign-offs, a not-applicable option with rationale, and links to workpapers and identified risks. Group financial statements, service organizations, initial audits, and going concern matters are addressed by dedicated sections that are marked not applicable when the circumstances do not exist.

Other QCM intended to be used in conjunction with the program DC7

  • The user firm's own system of quality management designed and implemented under SQMS No. 1, A Firm's System of Quality Management (QM section 10), including its policies for engagement quality reviews under SQMS No. 2. The program addresses engagement-level quality management under AU-C 220 and does not address firm-level quality management.
  • AuditFile's SQMS 1 firm-level quality management program (a separate AuditFile product), which a user firm may use to design, document, and evaluate its system of quality management.
  • The Engagement Quality Review checklist that AuditFile adds to every Advantage Audit audit engagement, which documents the engagement quality reviewer's procedures under SQMS No. 2 when the firm's policies require a review.
  • The AICPA Professional Standards (AU-C sections) and the AICPA Code of Professional Conduct, which the program cites and which user firms must consult directly; the program is not a substitute for them.

Relevant standards and interpretive guidance addressed by the program DC8

Auditing Standards Board (ASB) of the AICPA

The program addresses the Statements on Auditing Standards issued by the ASB and effective for audits of financial statements for periods ending on or before December 31, 2026, as codified in AICPA Professional Standards, AU-C sections 200 through 945, through SAS No. 150, External Confirmations (issued July 16, 2026). Every category, audit section, and step in the program cites the AU-C section and, where applicable, the paragraphs it reproduces or derives from; the citation allowlist maintained with the program lists each citation and its reviewer sign-off. SAS No. 145 (AU-C 315), SAS No. 146 (AU-C 220), SAS No. 147 (AU-C 210), and SAS No. 149 (AU-C 600) are fully incorporated. SAS No. 150 is incorporated on an early-implementation basis (see the standards issued but not yet effective). The AU-C sections not addressed, or not fully addressed, are listed below.

AICPA Professional Ethics Executive Committee (AICPA Code of Professional Conduct)

The program addresses the AICPA Code of Professional Conduct as in effect on September 28, 2026, in the context of its application to an audit engagement: the Independence Rule (ET 1.200.001), the Nonattest Services subtopic (ET 1.295), and the Responding to Noncompliance With Laws and Regulations interpretation (ET 1.180.010). The Code is not reproduced; the user firm's independence and ethics policies and the Code itself govern.

AICPA Auditing Standards Board (Statements on Quality Management Standards)

The program addresses the engagement-level requirements of SQMS No. 2, Engagement Quality Reviews (QM section 20), through the AU-C 220 steps and the Engagement Quality Review checklist. The firm-level requirements of SQMS No. 1, A Firm's System of Quality Management (QM section 10), and SQMS No. 3 are not addressed by this program (see the QCM used in conjunction).

Financial Accounting Standards Board (FASB)

The program is an auditing program; accounting standards are not its subject matter. Audit-area steps refer to FASB Accounting Standards Codification topics (for example, ASC 326, 330, 360, 450, 460, 606, 740, 842, 850, and 855) only to identify the accounting and disclosure matters the auditor evaluates, and those references reflect the Codification as of September 28, 2026. Accounting standards with disclosure requirements are addressed by the GAAP disclosure checklist practice aid, which is outside this Description.

Standards issued and effective but not addressed or not fully addressed DC9

Standard Status Why How the program treats it
AU-C 610, Using the Work of Internal Auditors partially addressed An internal audit function is uncommon in nonpublic commercial entities. The program requires the auditor to determine whether an internal audit function exists and to apply AU-C 610 directly when it does; the requirements for using internal auditors' work or direct assistance are not reproduced.
AU-C 701, Communicating Key Audit Matters in the Independent Auditor's Report not addressed Key audit matters are communicated only when the auditor is engaged to do so, which is not part of a standard audit of a nonpublic commercial entity. The reporting category directs the auditor to apply AU-C 701 directly if so engaged; an illustrative report including key audit matters is a practice aid outside the QCM.
AU-C 800, 805, 806, and 810 (special purpose frameworks; single statements and specific elements; reporting on contractual or regulatory compliance; summary financial statements) not addressed The program is designed for audits of a complete set of general purpose financial statements prepared in accordance with U.S. GAAP; these sections apply to other engagements or frameworks. Not reproduced; user firms must tailor the program and apply the sections directly when applicable.
AU-C 905, 910, 915, 920, 925, 930, 940, and 945 (restricted-use alerts; other-country frameworks; reports on application of requirements; letters for underwriters; SEC filings; interim financial information; integrated audits of internal control; exempt offering documents) not addressed These sections apply to engagements, circumstances, or reporting responsibilities outside a GAAS audit of a nonpublic commercial entity's annual financial statements. Not reproduced; the AU-C 265 communication includes the restriction on use that section requires.
AU-C 935, Compliance Audits not addressed Compliance audits are separate engagements performed under governmental audit requirements and are addressed by AuditFile's Governmental and Single Audit programs. Not reproduced.

Standards issued but not yet effective DC10

The user applying the program must evaluate each standard's applicability and effective date based on the period covered by each specific engagement.

Standard Effective date Addressed by the program? Early implementation
SAS No. 146, Quality Management for an Engagement Conducted in Accordance With Generally Accepted Auditing Standards (AU-C 220) Engagements conducted in accordance with GAAS for periods beginning on or after December 15, 2025 (effective for calendar-2026 year-ends; not yet effective for earlier fiscal years that may use this edition). Fully incorporated in the Engagement Quality Management category and the Engagement Quality Review checklist, with the extant AU-C 220 requirements replaced. Early implementation is permitted; SAS No. 146 does not prohibit early implementation (AU-C 220.10 states the effective date; the AICPA expects implementation concurrently with SQMS No. 1).
SAS No. 149, Special Considerations — Audits of Group Financial Statements (Including the Work of Component Auditors and Audits of Referred-to Auditors) (AU-C 600) Audits of group financial statements for periods ending on or after December 15, 2026. Fully incorporated in the Group Audits category, with the extant AU-C 600 requirements replaced; the category is completed only when the financial statements are group financial statements. Early implementation is permitted; SAS No. 149 does not prohibit early implementation (AU-C 600.14 states the effective date).
SAS No. 150, External Confirmations (amending AU-C 505 and AU-C 330) Audits of financial statements for periods ending on or after December 15, 2028 (issued July 16, 2026). Incorporated on an early-implementation basis in the External Confirmations and Cash categories (confirmation of cash and cash equivalents held by third parties, direct access to information maintained by a knowledgeable external source, use of intermediaries, and conditions for negative confirmations); the extant AU-C 505 requirements are otherwise retained. Steps derived from SAS No. 150 are identified as such. Early implementation is permitted.
SAS No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements (superseding AU-C 240) Audits of financial statements for periods ending on or after December 15, 2028 (approved by the ASB on August 20, 2026; publication of the final standard expected October 2026). Not incorporated. The Fraud category follows AU-C 240 as currently effective. SAS No. 151 is expected to be incorporated in the 2028 edition of the program once the final standard is published. Early implementation is permitted (to be verified against the final standard when published).
SQMS No. 1, A Firm's System of Quality Management; SQMS No. 2, Engagement Quality Reviews; SQMS No. 3, Amendments to QM Sections 10 and 20 Systems of quality management designed and implemented by December 15, 2025, with an evaluation of the system within one year of that date; SQMS No. 2 applies to engagements for periods beginning on or after December 15, 2025. Engagement-level aspects are addressed through AU-C 220 and the Engagement Quality Review checklist; firm-level requirements are not addressed by this program. Early implementation is permitted.

Policy for updating the QCM content DC11

AuditFile updates the Non-public Company program annually and generally releases a new edition each December for engagements with year-ends in the following calendar year, to reflect changes in standards and interpretive guidance, content enhancements, and corrections of errors. Interim updates to an edition are released when a Statement on Auditing Standards becomes effective during the edition year or when a content error is identified; every interim update re-dates this Description and is listed in its attachment.

Updates reach engagements created after the update; an engagement created earlier retains the content it was created with, and an engagement rolled forward from a prior year retains the prior year's tailored content (AuditFile warns at creation that duplicating an engagement does not apply program updates). Each engagement displays the edition it was created from, and this Description records the content digest of the edition it describes. The 2027 edition referenced in this Description was completed on September 28, 2026; it is a complete rewrite of the program, so no procedure-level comparison to the 2026 edition is presented (see the attachment).

User firm responsibilities DC12

User firms are responsible for the following:

  1. Determining whether the QCM are suitable for the user firm's purposes
  2. Understanding that the QCM are not intended to be a substitute for the standards and interpretive guidance, an evaluation thereof, or professional judgment
  3. Using the most up-to-date QCM available that are applicable in the circumstances, including accessing and using the most recent and effective relevant standards and interpretive guidance that are not addressed or not fully addressed by the QCM
  4. Properly implementing the QCM and using professional judgment in the application of the QCM based on the facts and circumstances (for example, of each engagement)
  5. Providing the appropriate training for the use of the QCM and performing the appropriate supervision and review procedures regarding the use of the QCM based on the skill, training, knowledge, and experience of individual users within the user firm
  6. Identifying that there may be certain facts, circumstances, risk factors, or specific issues that exist for a particular client, engagement, or user firm that may not be addressed by the QCM; in that case, understanding that the QCM will require tailoring and augmentation to address such facts, circumstances, risk factors, or specific issues
  7. Monitoring the activities of standard-setting bodies for changes that would affect the user firm, including amendments of standards and interpretive guidance and deferrals of effective dates
  8. Complying with relevant professional standards and interpretive guidance
  9. Understanding that the effectiveness of the QCM is dependent on the user firm fulfilling the preceding responsibilities and the effectiveness of its actions

Attachment: changes from the prior edition

  • The 2027 edition is a complete rewrite of the step content; every step reproduces or derives from an identified requirement or application paragraph. The 2026 category structure is retained (the same category names, groupings, financial statement section types, leadsheet numbers, and the Basic Procedures / Further Procedures / Conclusion sections in each audit area), so engagements roll forward from the 2026 edition and the AuditFile planning tools operate unchanged; three categories are added for the revised standards (Engagement Quality Management, Identifying and Assessing the Risks of Material Misstatement, Service Organizations).
  • Every category, audit section, and step now carries a standards citation (the 2026 edition cited about one step in five), and every step carries a content-type label distinguishing requirements, application material, AuditFile practice guidance, and generally accepted practice.
  • SAS No. 145 (AU-C 315) is incorporated in full, replacing the 2026 edition's summary risk-assessment steps, including inherent risk factors, the spectrum of inherent risk, significant classes of transactions, account balances, and disclosures, general IT controls, separate inherent and control risk assessments, and the stand-back evaluation; detection risk is no longer described as part of the risk assessment.
  • SAS No. 146 (AU-C 220) is incorporated through a new Engagement Quality Management category; the 2026 edition had no engagement-level quality management steps and used the superseded term "quality control".
  • SAS No. 149 (AU-C 600) is incorporated as a built-in Group Audits category based on the group engagement partner, component auditor, and referred-to auditor model; the 2026 edition offered a group audit add-in based on the superseded significant-component model.
  • SAS No. 150 (AU-C 505) is incorporated on an early-implementation basis, including the confirmation of cash held by third parties.
  • SAS No. 142 (AU-C 500), SAS No. 143 (AU-C 540), and SAS No. 144 (management's specialists and pricing information) are woven into the Accounting Estimates, Specialists and Audit Evidence, and audit-area categories rather than appearing as summary steps.
  • The 2026 edition's "SAS 148 Compliance Audits" steps were removed; AU-C 935 is not addressed by a GAAS financial statement audit program.
  • The management override of controls fraud risk is presented as a presumed significant risk that cannot be rebutted, and the required responses are performed on every audit.
  • Superseded terminology was removed ("quality control", "illegal acts", "audit risk reduced to an appropriate low level", blanket "SAS 134-140" citations).
  • The linked GAAP disclosure checklist practice aid is a new 2026 edition updated for ASUs issued through ASU 2026-03 (the 2026 program linked the 2023 edition); the 2025 edition is retained for prior-year reference.
  • Every citation in the program was cross-checked against the AICPA Professional Standards codification text (AU-C sections as amended through SAS No. 149) by two independent verifiers with a tie-breaker on disagreement before this Description was dated; the citation allowlist records the result.

How to read the program

Every category, audit section and step in the program carries a reference to the professional standard it reproduces or derives from, and every step is labeled with one of the following content types:

  • Requirement Reproduces or derives from a requirement of the cited standard.
  • Application material Reflects the application and other explanatory material of the cited standard.
  • AuditFile practice guidance AuditFile's practice guidance: a workflow or documentation step that is not itself a requirement of a professional standard.
  • Generally accepted practice Based on widely recognized or generally accepted practice rather than on a requirement of a professional standard.
Program edition 2027 · Description dated 2026-09-28 · content digest e6863cc31b1792727197459321d02482347ad6516cd54f5e0d430b02e23b27a0