The AICPA quality management peer review checklists have been available for several months. But the August 2026 Center for Plain English Accounting report brought them back into focus by clarifying how reviewers are expected to use them and where firms should expect closer attention.
Whether your firm is almost finished and wants a double-check, or you are just opening SQMS No. 1 and wondering what you actually need to get done, the checklists are worth reviewing.
See below for a breakdown on what these checklists encompass and how it affects your system of quality management.
If you are preparing for peer-review, I recommend focusing on five things:
The recent CPEA report makes one point especially clear: the risk assessment will matter. Because it drives the other components of the system, reviewers are expected to spend significant time understanding the firm's objectives, risks, responses, and how those pieces fit together.
Firms can use the AICPA template, PPC materials, software, an internally developed matrix, or another format (see details of the Risk Matrix I developed here).
Whatever format you use, the best advice I can offer is to make the linkage painfully clear.
Ideally, a peer reviewer should not have to hunt through multiple tabs, manuals, or disconnected documents to determine how an objective was considered, which risks were identified, what the firm is doing about those risks, and how those responses are monitored.
During my time in Big Four, I was trained to document through the eyes of a PCAOB inspector.
Clean formatting means fewer questions. If the reviewer can follow the logic quickly, there is less ambiguity, less back-and-forth, and less time spent chasing down how the pieces connect.
That traceability is one of the main reasons I built my Risk Assessment Matrix with pre-linked objectives, risks, and responses. The full toolkit carries that same linkage forward into suggested monitoring and evidence.
The peer review checklist reinforces why this step matters. The reviewer is looking for the required objectives, appropriate quality risks for those objectives, and responses designed to address those risks.
PRP 4600-QM evaluates whether the firm's system of quality management is suitably designed. It covers the risk assessment, the six components with prescribed quality objectives, monitoring and remediation, documentation, and the reviewer's overall design conclusion.
A “system” of quality management does not have to mean a dedicated software platform.
For many small to medium firms, the supporting documentation may simply be a practical set of Word, Excel, PDF, and existing firm records organized with the same logic as a clean audit file.
From a practical perspective, the documentation should work like a clean audit file. Someone unfamiliar with the firm or its system should be able to open the file, understand the design, and trace the support.
The CPEA report emphasizes that monitoring design should make sense in light of the firm's own risk assessment and responses - another reason to keep monitoring references visible within the risk assessment structure.
Design is only half the review.
Checklist PRP 4650-QM tests whether the firm's quality responses were implemented and operated effectively. The reviewer is not simply reading policies. They may select samples, inspect files, review correspondence, or interview personnel.
The operating effectiveness checklist uses three categories of procedures:
The April 2026 checklist clarifies that not every Key procedure must be performed. However, the CPEA expects the four risk assessment procedures to be performed in their entirety on most reviews.
A tracker may show that a task was marked complete. The signed form, dated communication, completed checklist, engagement documentation, or other underlying record is what supports that the activity actually occurred.
This distinction becomes important when a firm is preparing for its first peer review under the new standard. The operating effectiveness checklist is built around obtaining and testing that underlying support.
The August CPEA report highlights several procedures firms may want to review closely before peer review. This is not an all-inclusive list, but these are good places to look for gaps.
If the risk assessment is holding you up, use the two linked articles above as your starting point.
For firms further along, this is probably the fastest readiness exercise: work through the applicable Key procedures and ask whether the firm can produce the support a reviewer is likely to request.
I created two guides mapping the peer review checklists directly to the CC Consulting Risk Assessment Matrix and SQMS No. 1 Toolkit so firms can quickly see where the applicable questions are addressed and where the supporting documentation should live.
The goal is simple: make the documentation easier to follow and reduce unnecessary follow-up during peer review.
The guide tells you what the reviewer is likely to test. The Toolkit contains the workpapers designed to help you perform and document it.
Learn more about the SQMS No. 1 ResourcesIf you are looking for the shortest version of peer review readiness under SQMS No. 1, focus on two things:
Make the design easy to trace. Keep the evidence easy to produce.
Peer review is not just asking whether a policy exists. The reviewer is looking at why it is there, how it connects to the firm's risks, whether it operated, and what evidence supports that conclusion.
This article is intended for general educational purposes and reflects practical experience applying SQMS No. 1 and reviewing the AICPA peer review checklists. It is not authoritative AICPA guidance, does not guarantee a peer review result, and is not a substitute for reviewing the applicable professional standards, peer review guidance, and your firm's specific facts and circumstances.
Book a complimentary 30-minute call to see the Risk Assessment Matrix and the rest of the SQMS Toolkit, or email me for the Operating Effectiveness Guide.
Prefer email? caroline@carolinecast.cpa