CPA Firms
CPA Audit and Assurance Requests: An Intake Guide
Audit and assurance intake should identify the entity, engagement, period, requester, requested information, authorized channel, owner, and limits without making professional conclusions.

Identify the engagement before labeling the request
Capture the entity, service, period, applicable framework, engagement identifier, requester’s role, exact question, requested item, stated deadline, and channel. Do not call every financial-statement service an audit, or treat audit, review, compilation, preparation, attestation, and agreed-upon procedures as interchangeable. Support may explain an approved request process; it should not expand scope, decide whether a procedure is required, promise report issuance, or characterize the level of assurance. Route ambiguous service labels to the engagement owner.
Preserve evidence lineage without judging sufficiency
Record what was requested, by whom, when, through which approved channel, what was received, source as represented, file integrity signals, version, and custody. Support may confirm receipt in an authoritative system but should not decide relevance, reliability, completeness, authenticity, materiality, exception status, or whether audit evidence is sufficient and appropriate. Never alter source material, combine client assertions with auditor conclusions, or expose workpaper content to an unauthorized person. Rejected, duplicate, damaged, suspicious, or late items need controlled exception handling.
Respect independence and communication roles
Questions about relationships, nonattest services, fees, employment, governance, affiliates, and business interests may affect an independence analysis under the applicable rules. Support should preserve the facts and route them, not offer a clearance. For public-company audits, PCAOB and SEC requirements may govern particular communications, documentation, and independence; they do not automatically apply to every CPA engagement. Verify who may communicate with management, those charged with governance, an audit committee, component auditors, specialists, regulators, and third parties.
Control status language and handoffs
Define approved administrative stages such as request issued, client response received, assigned, under review, follow-up requested, and closed by the authorized team. None inherently means testing is complete, a misstatement is resolved, controls are effective, the report is ready, or an opinion will be unmodified. Tell the requester what the authoritative record says, its timestamp, the next administrative action, owner, and expected update without predicting conclusions. Track stale statuses, unauthorized workpaper disclosures, unsupported issuance dates, and handoffs without acceptance.
Build the control table
| Control | Support role | Authorized owner |
|---|---|---|
| Client facts | Capture minimum necessary information | Validate identity and engagement |
| Explanation | Use dated approved sources | Approve professional wording |
| Consequential work | Preserve request and route | Advise, prepare, attest, represent, or execute |
| Uncertainty | State limits and escalate | Investigate and respond |
Govern professional knowledge and handoff
Every answer should point to a dated, owned source. Separate public education, firm policy, engagement terms, client statements, source documents, accounting records, workpapers, tax return information, and professional conclusions. Require qualified review for accounting treatment, audit and assurance, independence, ethics, licensure, tax advice, preparation, filing, representation, Section 7216, fees, deadlines, privacy, security, identity, accessibility, and jurisdiction questions. Log the knowledge version, verification state, engagement boundary, receiving owner, and client confirmation. A summary helps only when its provenance can be checked and the authorized destination accepts the matter.
Protect client data and service resilience
Collect the minimum information needed in approved channels. Define identity verification, access, engagement isolation, retention, redaction, recording, consent, export, deletion, workpaper, document, and vendor controls under the firm’s security program. Provide accessible interaction, effective communication, error recovery, a human alternative, and reviewed language support without inventing a language count. Test outages, stale sources, duplicate uploads, malicious prompts, attempted credential disclosure, impersonation, suspicious instructions, conflicting engagement records, and failed handoffs with synthetic data. Record limitations, owners, incident paths, and rollback procedures.
Apply scope and qualified review
This article provides general operational information, not accounting, audit, assurance, attest, tax, legal, financial, representation, licensing, ethics, independence, privacy, security, identity, accessibility, or compliance advice. Client, entity, engagement, service, framework, period, jurisdiction, practitioner status, authorization, contract, systems, facts, and current standards control. A configured conversational system may assist approved intake and routing, but this article does not claim LumiTalk accepts an engagement; clears conflicts or independence; performs bookkeeping, accounting, audit, review, compilation, attestation, tax preparation, filing, or representation; makes a professional judgment; issues a report or opinion; executes a payment; validates consent; guarantees deadlines, outcomes, security, or compliance; reads live client, accounting, tax, or audit systems; or provides exact pricing, availability, language, or integration coverage.
Primary sources
Use current primary sources as the factual floor, then obtain firm, engagement, service, client, entity, framework, period, practitioner, and jurisdiction-specific qualified review. AICPA Standards and Statements · PCAOB AS 1301: Communications with Audit Committees · PCAOB AS 1215: Audit Documentation · SEC Qualifications of Accountants
Continue through the CPA Firms cluster
Use the hubs and service page for cluster context, then compare adjacent guides before implementing a workflow. CPA Firms resource hub · Tax & Accounting resource hub · LumiTalk for CPA-firm operations · CPA Firm Customer Support Operations Guide · Accounting Close and Client Status Support · CPA Firm Support Software Checklist
Quick answers
Frequently asked
Is every CPA financial-statement service an audit?
No. Audit, review, compilation, preparation, attestation, and other services have different scopes and professional requirements.
Can support decide whether audit evidence is sufficient?
No. Support may record and route receipt; relevance, reliability, sufficiency, and conclusions belong with the engagement team.
Do PCAOB rules apply to every CPA audit?
No. Applicability depends on the engagement and regulatory context; qualified professional review is required.
Can support promise an audit report date?
Only authorized engagement leadership and supported records can communicate a commitment, without promising the opinion or result.
CPA Audit and Assurance Request Intake Guide
Test one evidence request from authorized issuance through secure receipt, lineage, professional review, exception handling, and requester update.








