CPA AUDITING & ATTESTATION (AUD) • ETHICS, PROFESSIONAL RESPONSIBILITIES AND GENERAL PRINCIPLES

AICPA Code Of Professional Conduct — Apply AICPA Code Of Professional Conduct

The ethical foundation that governs every CPA's professional judgment, independence, and public trust obligations.

Historical Context & Motivation

The accounting profession's credibility rests on the perception that practitioners serve the public interest with integrity and objectivity. The American Institute of Certified Public Accountants (AICPA) has maintained a Code of Professional Conduct since the early twentieth century, evolving it in response to economic crises, corporate scandals, and shifts in the regulatory landscape. Understanding the historical trajectory of this code is essential for any CPA candidate, because each revision reflects lessons learned from failures in professional ethics that eroded public trust in financial reporting.

Before the AICPA formalized its ethical standards, accounting was a loosely regulated trade. As capital markets expanded and investors relied more heavily on audited financial statements, the need for a uniform code of ethics became evident. The profession recognized that self-regulation through a robust ethical framework was preferable to heavy-handed government oversight, provided that CPAs held themselves to standards that genuinely protected the public.

1887
Formation of the AAPA
The American Association of Public Accountants (AAPA), the predecessor to the AICPA, was founded, marking the first organized effort to professionalize accounting in the United States.
1917
Early Ethical Rules Adopted
The organization adopted its first formal rules of professional conduct, addressing issues like advertising restrictions and contingent fees, establishing the idea that CPAs owed duties beyond those to their immediate clients.
1973
Restructured Code of Ethics
The AICPA restructured its code to include broad ethical principles alongside enforceable rules, creating a two-tier framework that balanced aspirational guidance with minimum standards of conduct.
2002
Sarbanes-Oxley Act
Following the Enron and WorldCom scandals, Congress passed SOX, creating the PCAOB and imposing stricter independence rules. The AICPA subsequently revised its code to align with these heightened regulatory expectations.
2014
Codification & Modernization
The AICPA completed a comprehensive recodification of its Code of Professional Conduct, reorganizing it by topic and member type, making it more accessible and aligned with the International Ethics Standards Board for Accountants (IESBA) framework.

The central question the Code addresses is deceptively simple: How should a CPA behave when professional obligations, client demands, and personal interests conflict? The Code provides a conceptual framework approach alongside specific rules, guiding practitioners through ethical dilemmas that arise in audit, tax, consulting, and other professional engagements.

Core Principles & Definitions

The AICPA Code of Professional Conduct is structured around six foundational principles that set the aspirational tone for all members. These principles are not directly enforceable but serve as the philosophical underpinning of the more specific rules and interpretations that follow. A CPA who internalizes these principles is far better equipped to navigate novel ethical situations that the rules may not explicitly address.

1

Responsibilities

CPAs must exercise sensitive professional and moral judgments in all activities. The principle recognizes that CPAs bear a collective responsibility to the profession's reputation and the public it serves.
2

The Public Interest

CPAs must act in a way that serves the public interest, honoring the public trust, and demonstrating a commitment to professionalism. This principle elevates the profession's duty above the narrow interests of any individual client.
3

Integrity

Members must be honest and candid within the constraints of client confidentiality. Service and public trust should not be subordinated to personal gain or advantage.
4

Objectivity & Independence

CPAs must maintain objectivity and be free of conflicts of interest. For those in public practice performing attest services, independence in fact and appearance is mandatory.
5

Due Care & Scope and Nature of Services

CPAs must observe technical and ethical standards, continually improve competence and quality of services, and ensure the scope of services rendered is consistent with the Code's principles.

The recodified Code is organized into three main parts: Part 1 — Members in Public Practice, Part 2 — Members in Business, and Part 3 — Other Members (including retired and inactive members). Each part contains topical sections covering independence, integrity, objectivity, and other relevant areas. The conceptual framework embedded within each part requires CPAs to identify threats to compliance with the rules, evaluate whether those threats are at an acceptable level, and apply safeguards to bring threats down to an acceptable level when necessary.

KEY TAKEAWAY
Think of the AICPA Code like the structural engineering standards for a bridge: the six principles are the design philosophy (safety, load-bearing capacity, durability), while the specific rules are the building codes that spell out minimum steel thickness, bolt spacing, and inspection intervals. An engineer who understands only the codes but not the philosophy will struggle when facing an unusual terrain; similarly, a CPA who memorizes the rules without grasping the principles will falter when encountering novel ethical dilemmas.

Visual Explanation — The Conceptual Framework

The AICPA's conceptual framework approach is the central mechanism by which CPAs evaluate and resolve ethical threats. Rather than attempting to enumerate every possible scenario in the rules, the framework provides a structured decision-making process that applies universally. The following diagram illustrates the sequential steps a CPA takes when confronted with a potential ethical conflict.

The flowchart shows the AICPA conceptual framework decision process. A CPA first identifies the type of threat (listed in the legend on the left: self-interest, self-review, advocacy, familiarity, undue influence, and management participation), evaluates significance, applies safeguards if necessary, and either proceeds with the engagement or declines it.

As the diagram illustrates, the framework is iterative rather than linear. If the initial evaluation at Step 3 reveals that threats are not at an acceptable level, the CPA must identify and apply safeguards — actions or measures that eliminate the threat or reduce it to an acceptable level. Safeguards can be institutional (such as firm-wide quality control policies), regulatory (such as PCAOB oversight), or engagement-specific (such as removing a team member with a financial interest in the client). If no combination of safeguards can reduce the threat sufficiently, the CPA is ethically obligated to decline or withdraw from the engagement.

How the Code Works — Independence & Threats in Depth

While the AICPA Code is not a mathematical framework, its application follows a rigorous analytical structure. The most critical and frequently tested area of the Code concerns independence, which applies to CPAs performing attest services — audits, reviews, examinations, and other engagements that require the CPA to issue a report expressing a conclusion about the reliability of a subject matter. Independence has two dimensions: independence in mind (fact) and independence in appearance. The former refers to the state of mind that permits the CPA to act with integrity and exercise objectivity and professional skepticism; the latter means the avoidance of circumstances that would cause a reasonable and informed third party to conclude that the CPA's integrity, objectivity, or professional skepticism has been compromised.

The Six Categories of Threats to Independence

The six threat categories under the AICPA conceptual framework
Threat CategoryDefinitionExample
Self-InterestA financial or other interest will inappropriately influence the CPA's judgment or behavior.A CPA owns stock in an audit client, or the firm's fee from a single client constitutes a large percentage of total revenue.
Self-ReviewThe CPA reviews work the CPA or the firm previously performed, reducing the likelihood of identifying errors.A firm that designed a client's accounting system then audits the financial statements produced by that system.
AdvocacyThe CPA promotes a client's position to the point that objectivity is compromised.A CPA firm acts as an investment advisor promoting the client's stock while auditing the same client.
FamiliarityA long or close relationship with a client leads the CPA to become too sympathetic to the client's interests.The lead audit partner has served the same client for 15 years, developing close personal friendships with management.
Undue InfluenceThe CPA is deterred from acting objectively by actual or perceived pressures, including attempts to exercise coercive influence.A client threatens to switch firms if the auditor does not accept an aggressive accounting treatment.
Management ParticipationThe CPA assumes a management role or performs management functions for the client.An auditor makes journal entries or approves transactions on behalf of the audit client without client oversight.

Safeguards — The Countermeasures

Safeguards fall into three broad categories. Safeguards created by the profession, legislation, or regulation include education and training requirements, continuing professional education, professional standards and monitoring, external review of the firm's quality control system, and legislation governing the independence requirements of the firm. Safeguards implemented by the client include competent management that makes significant managerial decisions, an effective audit committee that oversees the external auditor relationship, and internal policies that emphasize fair financial reporting. Safeguards implemented by the firm include tone at the top that emphasizes independence, firm-wide policies on partner rotation, engagement quality review by a second partner, and consultation with internal or external experts on complex independence questions.

Structure & Classification of the Code

Understanding the organizational architecture of the AICPA Code is critical for efficient navigation, both on the CPA exam and in practice. The 2014 recodification organized the Code into a topical structure that mirrors how practitioners actually encounter ethical issues. The following diagram illustrates the hierarchical structure of the Code and how its components interrelate.

The organizational hierarchy of the AICPA Code. The Preface contains the six principles and key definitions. Part 1 governs members in public practice (auditing firms), Part 2 governs members in business (corporate accountants), and Part 3 governs other members. Each part contains numbered topical sections covering the same broad areas — integrity, objectivity, confidentiality, and professional behavior — tailored to the unique context of each member category.

Within each topical section, the Code follows a consistent internal hierarchy. Each section typically includes a rule (the enforceable minimum standard), one or more interpretations (guidance on how the rule applies in specific circumstances), and occasionally other guidance (nonauthoritative explanatory material). Members who depart from interpretations bear the burden of justifying that departure. The numbering system (e.g., ET §1.200.001) allows practitioners to quickly locate relevant guidance: the first digit indicates the part, the three-digit code indicates the topic, and the final three digits identify the specific interpretation.

💡 EXAM TIP
On the CPA AUD exam, you will frequently be tested on your ability to correctly identify which Part of the Code applies to a given scenario. Remember: independence requirements apply primarily to Part 1 — Members in Public Practice performing attest services. Members in business (Part 2) are not required to be independent of their employer, but they must maintain integrity and objectivity.

Worked Example — Applying the Conceptual Framework

The following scenario demonstrates how a CPA would apply the AICPA conceptual framework to evaluate an independence threat and determine the appropriate course of action.

📋 SCENARIO
Sarah Chen, CPA, is the engagement partner for the audit of TechVenture Inc., a publicly traded software company. Sarah's husband recently inherited 500 shares of TechVenture stock, valued at approximately $25,000. TechVenture's audit committee has expressed satisfaction with Sarah's work and wants her to continue leading the engagement. What should Sarah do under the AICPA Code?
Applying the AICPA Conceptual Framework
1
Step 1 — Identify the Relevant RuleSarah is a member in public practice performing an attest service (audit), so Part 1 of the Code applies. The relevant section is ET §1.200 — Independence. Under the independence rules, a covered member (which includes the engagement partner and their immediate family) must not have a direct financial interest in an attest client, regardless of materiality.
Applicable Rule: ET §1.200 — Independence; Direct Financial Interest prohibition
2
Step 2 — Identify the ThreatSarah's husband's ownership of TechVenture stock constitutes a direct financial interest held by an immediate family member of a covered member. This creates a self-interest threat to independence, because Sarah might consciously or subconsciously favor reporting that supports TechVenture's stock price.
Threat Identified: Self-interest threat from direct financial interest of immediate family
3
Step 3 — Evaluate the Threat LevelUnder the AICPA Code, a direct financial interest in an attest client held by a covered member (or the covered member's immediate family) is an absolute prohibition — it is deemed so significant that no safeguard can reduce it to an acceptable level. This is true regardless of the dollar amount: even $1 of direct financial interest impairs independence. The conceptual framework recognizes that certain threats are simply too severe to mitigate.
Threat Level: Unacceptable — No safeguard sufficient; absolute prohibition applies
4
Step 4 — Determine the Required ActionSarah has a limited number of options. She must either: (a) have her husband dispose of the TechVenture shares before the period of the professional engagement begins (or immediately upon learning of the interest), or (b) withdraw from the engagement entirely. If the shares were inherited during the period of engagement, the Code provides a brief window — typically before the next set of financial statements is issued — for the shares to be disposed of. During that window, the covered member should not participate in the engagement. Since the audit committee wants Sarah to continue, the most practical resolution is for her husband to sell the 500 shares promptly.
Required Action: Dispose of the direct financial interest immediately or withdraw from the engagement
5
Step 5 — Document and CommunicateSarah should document the threat, the analysis, and the resolution in the engagement file. She should communicate the matter to the firm's ethics partner or independence compliance function. If her husband disposes of the shares, Sarah should obtain evidence of the sale and confirm that no other independence impairments exist before resuming engagement responsibilities. The firm should also evaluate whether the threat affected any work already performed during the period in which the shares were held.
Best Practice: Document, communicate to firm leadership, verify disposal, assess prior work

AICPA Code vs. Other Ethical Frameworks

The AICPA Code does not exist in isolation. CPAs must navigate a complex regulatory environment where multiple ethical frameworks may apply simultaneously. Understanding the similarities and differences between the AICPA Code and other regulatory frameworks — particularly the PCAOB independence rules, SEC regulations, and the IESBA Code of Ethics — is important for practitioners and exam candidates alike.

Comparison of major ethical and independence frameworks applicable to CPAs
FeatureAICPA CodePCAOB / SEC RulesIESBA Code
ApplicabilityAll AICPA members (public practice, business, and other)Registered firms auditing SEC issuers (public companies)Professional accountants worldwide who adopt IFAC standards
ApproachPrinciples-based with conceptual framework and specific rulesPredominantly rules-based with bright-line prohibitionsPrinciples-based conceptual framework; closely aligned with AICPA
Partner RotationRequired for certain engagements (e.g., 7 years for SEC audit clients under PCAOB rules adopted by reference)Mandatory 5-year rotation for lead and concurring partners; 5-year cooling-off period7-year rotation with 5-year cooling-off for public interest entities
Non-Audit ServicesPermitted if safeguards are applied and management takes responsibilityMany explicitly prohibited (e.g., bookkeeping, internal audit outsourcing, management functions for SEC audit clients)Evaluated through conceptual framework; some prohibitions for public interest entities
EnforcementProfessional Ethics Division of AICPA; state boards of accountancySEC enforcement actions; PCAOB inspections and disciplinary proceedingsNational member bodies (varies by jurisdiction)
KEY TAKEAWAY
When a CPA audits a publicly traded company, the most restrictive set of rules applies. Think of it like driving through multiple states on a road trip: if State A sets the speed limit at 70 mph and State B at 55 mph, you must drive at 55 in State B. Similarly, if the AICPA Code permits a certain non-audit service but the SEC/PCAOB rules prohibit it for issuers, the CPA must comply with the more restrictive SEC/PCAOB prohibition. This 'most restrictive rule' principle is a critical concept for the CPA exam.

Connection to Advanced Regulatory & Ethical Theory

The AICPA Code's conceptual framework approach represents a broader philosophical shift in professional ethics regulation — moving from a purely rules-based model to a principles-based model. This evolution mirrors developments in international financial reporting (IFRS vs. U.S. GAAP) and reflects a recognition that static rules cannot anticipate every ethical dilemma. Advanced study in professional ethics explores how this tension between rules-based and principles-based regulation shapes practitioner behavior, enforcement patterns, and the evolution of the profession itself.

Current AICPA Code features vs. emerging ethical and regulatory directions
DimensionAICPA Code (Current)Advanced / Emerging Frameworks
Ethics ModelHybrid: aspirational principles + enforceable rules + conceptual frameworkIncreasing emphasis on behavioral ethics, cognitive bias awareness, and ethical decision-making training
Technology ImpactCode addresses traditional services; limited guidance on AI, data analytics, blockchain-based attest servicesEmerging guidance on ethical AI use in audit, data privacy obligations, and independence in technology-driven services
Global ConvergenceAligned with IESBA framework in structure but significant differences in specific rulesOngoing convergence efforts; IESBA revisions to independence standards increasingly influencing AICPA positions
Non-Assurance ServicesConceptual framework permits many services with safeguardsGrowing scrutiny of consulting revenue in audit firms; EU audit reform directs toward narrower permissible services

As the profession continues to evolve — with expanding roles in sustainability reporting, cybersecurity attestation, and digital asset verification — the AICPA Code will likely undergo further revisions. CPA candidates should understand that the Code is a living document, subject to ongoing interpretation and amendment. The underlying principles, however, remain durable: the profession's legitimacy depends on public trust, and public trust depends on demonstrable independence, integrity, and competence.

Practice Problems

1
Which of the following is a fundamental principle of the AICPA Code of Professional Conduct that requires a member to be honest and candid within the constraints of client confidentiality?
2
A CPA in public practice is approached by a potential client to perform a financial statement audit. The CPA's spouse owns a material direct financial interest in the potential client. Under the AICPA Code of Professional Conduct, what action should the CPA take?
3
A CPA firm has been engaged to audit the financial statements of Alpha Co. During the audit period, a manager on the engagement team learns that her close relative was recently hired as the controller of Alpha Co. Under the AICPA Code of Professional Conduct, the firm's independence is most likely impaired if the close relative is in a position to:
4
Baker, CPA, is a partner in a CPA firm that audits Omega Corp. Baker has been offered a position on Omega Corp.'s board of directors as a non-executive member. Baker would not receive any compensation other than a standard board fee. Baker believes serving on the board would help the firm better understand Omega's operations and improve audit quality. Under the AICPA Code of Professional Conduct, which of the following best describes the effect of Baker accepting the board position?
5
Davis & Associates, CPAs, performs the annual audit of Gamma Industries. During the current year, the following situations exist: I. A staff auditor on the engagement recently inherited 50 shares of Gamma stock (immaterial to the auditor's net worth) and plans to sell the shares within 30 days of becoming aware of the inheritance. II. The firm provides Gamma with tax compliance services in which the firm prepares and signs the corporate tax return based on information provided by Gamma's management, who reviews and approves the return before filing. III. A retired partner of the firm, who receives a fixed retirement benefit not dependent on firm revenues, serves on Gamma's board of directors. Which of the above situations, considered individually, would impair the firm's independence under the AICPA Code of Professional Conduct?

Summary — AICPA Code of Professional Conduct

The AICPA Code of Professional Conduct is built upon six foundational principles — Responsibilities, Public Interest, Integrity, Objectivity and Independence, Due Care, and Scope and Nature of Services — which provide the aspirational framework for all CPA conduct. The Code is organized into three parts (Members in Public Practice, Members in Business, and Other Members), each containing topical sections that address independence, integrity, objectivity, confidentiality, and professional behavior. The conceptual framework is the analytical engine of the Code: CPAs identify threats (self-interest, self-review, advocacy, familiarity, undue influence, management participation), evaluate their significance, and apply safeguards to reduce threats to an acceptable level — or decline the engagement if safeguards are insufficient.

For CPA exam purposes, remember that independence requirements apply only to members performing attest services, that direct financial interests in attest clients are absolutely prohibited for covered members regardless of materiality, and that when multiple regulatory frameworks apply (AICPA, PCAOB, SEC), the CPA must follow the most restrictive rule. The Code is a living document that continues to evolve as the profession expands into new service areas, but its core commitment to protecting the public interest through ethical self-regulation remains constant.

Varsity Tutors • CPA Auditing & Attestation (AUD) • AICPA Code Of Professional Conduct — Apply AICPA Code Of Professional Conduct