← Resources

What Will Your Peer Reviewer Look For Under SQMS No. 1?

September 23, 2026
Recent peer review update

The AICPA quality management peer review checklists have been available for several months. But the August 2026 Center for Plain English Accounting report brought them back into focus by clarifying how reviewers are expected to use them and where firms should expect closer attention.

Whether your firm is almost finished and wants a double-check, or you are just opening SQMS No. 1 and wondering what you actually need to get done, the checklists are worth reviewing.

Two checklists drive the peer review related to SQMS No. 1:

Design
Is the system appropriately designed?
Operating Effectiveness
Did the firm actually implement and operate it?

See below for a breakdown on what these checklists encompass and how it affects your system of quality management.

What absolutely has to be done?

If you are preparing for peer-review, I recommend focusing on five things:

  1. 1Finish and document the risk assessment.
  2. 2Make the linkage clear:Objective → Risk → Response (i.e. policy/procedure) → Monitoring / Evidence.
  3. 3Make sure the firm's policies and procedures reflect what the firm actually does.
  4. 4Perform monitoring and retain the underlying evidence.
  5. 5Review the applicable Key procedures in PRP 4650-QM and make sure you can produce the support a reviewer is likely to request.
The rest of this article breaks those five things down.
1

Start with traceability in the risk assessment

The recent CPEA report makes one point especially clear: the risk assessment will matter. Because it drives the other components of the system, reviewers are expected to spend significant time understanding the firm's objectives, risks, responses, and how those pieces fit together.

The focusIf you are trying to decide what needs attention first, start with the risk assessment. Then make sure you can show evidence that the resulting policies and procedures actually operated.

Firms can use the AICPA template, PPC materials, software, an internally developed matrix, or another format (see details of the Risk Matrix I developed here).

Whatever format you use, the best advice I can offer is to make the linkage painfully clear.

The chain should be obvious

Quality Objective
→
Quality Risk
→
Response
→
Monitoring / Evidence

Ideally, a peer reviewer should not have to hunt through multiple tabs, manuals, or disconnected documents to determine how an objective was considered, which risks were identified, what the firm is doing about those risks, and how those responses are monitored.

During my time in Big Four, I was trained to document through the eyes of a PCAOB inspector.

Clean formatting means fewer questions. If the reviewer can follow the logic quickly, there is less ambiguity, less back-and-forth, and less time spent chasing down how the pieces connect.

That traceability is one of the main reasons I built my Risk Assessment Matrix with pre-linked objectives, risks, and responses. The full toolkit carries that same linkage forward into suggested monitoring and evidence.

If the risk assessment is where your firm is stuck, start here:

The peer review checklist reinforces why this step matters. The reviewer is looking for the required objectives, appropriate quality risks for those objectives, and responses designed to address those risks.

2

What does the Design Checklist actually test?

PRP 4600-QM evaluates whether the firm's system of quality management is suitably designed. It covers the risk assessment, the six components with prescribed quality objectives, monitoring and remediation, documentation, and the reviewer's overall design conclusion.

First, what exactly is a “system” of quality management?

A “system” of quality management does not have to mean a dedicated software platform.

For many small to medium firms, the supporting documentation may simply be a practical set of Word, Excel, PDF, and existing firm records organized with the same logic as a clean audit file.

From a practical perspective, the documentation should work like a clean audit file. Someone unfamiliar with the firm or its system should be able to open the file, understand the design, and trace the support.

For “design” the peer reviewer is looking for:

  • All required quality objectives are addressed.
  • Appropriate quality risks have been identified and assessed.
  • Responses are designed to address those risks, including the specified responses required by SQMS No. 1.
  • Monitoring and remediation are appropriately designed.
  • Documentation is sufficient to support understanding, operation, monitoring, and evaluation of the system.

The CPEA report emphasizes that monitoring design should make sense in light of the firm's own risk assessment and responses - another reason to keep monitoring references visible within the risk assessment structure.

Quick Check
Can someone unfamiliar with your SQM open the risk assessment and quickly answer:
Which objectives are applicable?
Which risks threaten each objective?
What responses address the risk?
How are those responses monitored?
If not, the documentation may be harder to review than it needs to be.
3

Operating effectiveness is where the evidence matters

Design is only half the review.

Checklist PRP 4650-QM tests whether the firm's quality responses were implemented and operated effectively. The reviewer is not simply reading policies. They may select samples, inspect files, review correspondence, or interview personnel.

Three types of testing procedures

The operating effectiveness checklist uses three categories of procedures:

Key procedures
Core testing procedures.
→
Enhanced procedures
Additional testing when the reviewer needs more evidence.
→
Alternative procedures
Customized procedures for unique circumstances.

The April 2026 checklist clarifies that not every Key procedure must be performed. However, the CPEA expects the four risk assessment procedures to be performed in their entirety on most reviews.

A tracker is not the evidence.

A tracker may show that a task was marked complete. The signed form, dated communication, completed checklist, engagement documentation, or other underlying record is what supports that the activity actually occurred.

This distinction becomes important when a firm is preparing for its first peer review under the new standard. The operating effectiveness checklist is built around obtaining and testing that underlying support.

4

Other areas the CPEA says deserve a closer look

The August CPEA report highlights several procedures firms may want to review closely before peer review. This is not an all-inclusive list, but these are good places to look for gaps.

  • Monitoring and remediation: The report specifically flags the sufficiency and timeliness of monitoring, the materials used to perform monitoring, findings and deficiencies, corrective actions, and follow-up on those actions.
  • Communication: Reviewers may look at whether changes to the SQM were communicated timely and whether monitoring results, peer review results, regulatory feedback, roles, and responsibilities were communicated appropriately.
  • Engagement performance and resources: The CPEA also calls attention to areas such as EQR documentation, in-house CPE and instructor qualifications, compensation and advancement considerations, and partner approval of engagement teams.
  • Documentation: The documentation questions are required for system reviews. The CPEA recommends firms make sure appropriate documentation exists for every applicable item, with additional attention to the annual evaluation and root cause analysis because those requirements are new under SQMS No. 1.
5

What should your firm do now?

Still implementing
Focus on design.
  1. 1Finish the risk assessment.
  2. 2Make the linkage obvious: Objective > Risk > Response > Monitoring / Evidence.
  3. 3Confirm the specified responses required by SQMS No. 1 are included.
  4. 4Make sure policies and procedures reflect how the firm actually operates.
  5. 5Identify what evidence the important responses will create.
  6. 6Design monitoring around the firm's actual risks and responses.

If the risk assessment is holding you up, use the two linked articles above as your starting point.

Already operating
Focus on evidence.
  1. 1Download and review PRP 4650-QM from the AICPA.
  2. 2Work through the applicable Key procedures in PRP 4650-QM and identify the underlying documentation or evidence you would produce for each one.
  3. 3Make sure the evidence actually exists and is easy to locate.
  4. 4Review monitoring findings, deficiencies, corrective actions, and follow-up.
  5. 5Organize the file so a reviewer can trace the system without rebuilding it.

For firms further along, this is probably the fastest readiness exercise: work through the applicable Key procedures and ask whether the firm can produce the support a reviewer is likely to request.

6

For Users of the CC Consulting Risk Matrix or SQMS No. 1 Toolkit

I created two guides mapping the peer review checklists directly to the CC Consulting Risk Assessment Matrix and SQMS No. 1 Toolkit so firms can quickly see where the applicable questions are addressed and where the supporting documentation should live.

The goal is simple: make the documentation easier to follow and reduce unnecessary follow-up during peer review.

  • For the design checklist [PRP 4600-QM], the guide maps where the reviewer can find and confirm the firm's quality objectives, risks, responses, monitoring design, and required documentation.
  • For the operating effectiveness checklist [PRP 4650-QM], I mapped the “Key procedures” to:
The policy being tested
→
The toolkit workpaper
→
The underlying evidence the firm should be able to produce
A locator, not an assuranceThe guide shows where the documentation and evidence should live. It does not guarantee a peer review result. The firm still has to tailor the system, perform the work, retain the evidence, and support the conclusions. The peer reviewer applies professional judgment.
Design Checklist Coverage Guide
See how PRP 4600-QM maps to the Risk Matrix and Toolkit.
View the Guide
Operating Effectiveness Guide
See how the Key procedures map to policies, workpapers, and evidence.
Email Me for a Free Copy

The guide tells you what the reviewer is likely to test. The Toolkit contains the workpapers designed to help you perform and document it.

Learn more about the SQMS No. 1 Resources

Final takeaway

If you are looking for the shortest version of peer review readiness under SQMS No. 1, focus on two things:

Make the design easy to trace. Keep the evidence easy to produce.

Quality Objective
→
Quality Risk
→
Response
→
Monitoring / Evidence

Peer review is not just asking whether a policy exists. The reviewer is looking at why it is there, how it connects to the firm's risks, whether it operated, and what evidence supports that conclusion.

This article is intended for general educational purposes and reflects practical experience applying SQMS No. 1 and reviewing the AICPA peer review checklists. It is not authoritative AICPA guidance, does not guarantee a peer review result, and is not a substitute for reviewing the applicable professional standards, peer review guidance, and your firm's specific facts and circumstances.

Next step

Get your file ready for peer review.

Book a complimentary 30-minute call to see the Risk Assessment Matrix and the rest of the SQMS Toolkit, or email me for the Operating Effectiveness Guide.

Prefer email? caroline@carolinecast.cpa