CPA AUDITING & ATTESTATION (AUD) • ETHICS, PROFESSIONAL RESPONSIBILITIES AND GENERAL PRINCIPLES

Independence Requirements — Apply GAO And Department Of Labor Independence Requirements

Understanding how government auditing and employee benefit plan standards impose stricter independence rules than the AICPA framework alone.

Historical Context & Motivation

The concept of auditor independence has been central to the accounting profession since its earliest days, but the federal government's demand for heightened independence standards arose from a distinct set of concerns. When auditors examine entities that receive public funds—whether federal agencies, state programs, or employee benefit plans covering millions of workers—the stakes extend well beyond shareholders to encompass taxpayers, plan participants, and the broader public interest. The Government Accountability Office (GAO) and the Department of Labor (DOL) each developed their own independence frameworks to address perceived gaps in the AICPA's Code of Professional Conduct, reflecting the principle that greater public trust requires more rigorous safeguards against conflicts of interest.

1972
First Government Auditing Standards
The U.S. Comptroller General issued the first edition of Government Auditing Standards (the "Yellow Book"), establishing that auditors of government entities must meet independence requirements beyond those of the AICPA.
1974
ERISA Enacted
The Employee Retirement Income Security Act (ERISA) was signed into law, granting the DOL authority to regulate audits of employee benefit plans and define auditor independence for those engagements.
2002
Sarbanes-Oxley Act
SOX reinforced independence concepts across federal oversight regimes. The PCAOB's creation influenced the GAO's subsequent Yellow Book revisions by raising the bar for non-audit services restrictions.
2011
Yellow Book Major Revision
The GAO substantially revised Government Auditing Standards, introducing a more structured conceptual framework for independence threats and safeguards, while tightening restrictions on non-audit services.
2022
DOL Guidance Updates
The DOL continued refining its independence interpretations for ERISA plan audits, reflecting evolving financial relationships and plan structures in the modern employee benefits landscape.

The critical question this lesson addresses is: when an auditor must comply with GAO or DOL independence requirements—rather than or in addition to the AICPA Code—what specific restrictions and conceptual frameworks apply, and how do the various standards interact? Understanding these layered requirements is essential for CPA candidates, because a single engagement can trigger overlapping obligations from multiple standard-setters simultaneously.

Core Principles & Definitions

Both GAO and DOL independence requirements rest on the foundational premise that an auditor must be free from relationships that could impair—or could appear to impair—objectivity. However, the specific conceptual architecture differs in important ways from the AICPA framework. The GAO's Yellow Book employs a threats-and-safeguards approach that mirrors elements of the International Ethics Standards Board for Accountants (IESBA), while the DOL's independence requirements under ERISA are codified in regulations and advisory opinions that define specific prohibited relationships.

1

Independence in Mind

The state of mind that permits an auditor to perform the engagement without being affected by influences that compromise professional judgment. Both GAO and DOL require this as a baseline, though neither uses this exact AICPA terminology.
2

Independence in Appearance

The avoidance of circumstances that would cause a reasonable and informed third party to conclude that an auditor's integrity, objectivity, or professional skepticism has been compromised. The GAO explicitly emphasizes this dimension.
3

Conceptual Framework (GAO)

The Yellow Book requires auditors to identify threats to independence (self-interest, self-review, bias, familiarity, undue influence, management participation, structural), evaluate their significance, and apply safeguards to reduce them to an acceptable level.
4

DOL Prohibited Relationships

Under ERISA and DOL regulations (29 CFR § 2509.75-9), specific financial and business relationships between the auditor and the plan, plan sponsor, or plan administrator are categorically prohibited, including direct financial interests and certain loan arrangements.
5

Most Restrictive Standard Applies

When multiple independence standards apply to a single engagement, the auditor must comply with the most restrictive requirement. For example, a government employee benefit plan audit may require compliance with AICPA, GAO, and DOL standards simultaneously.
KEY TAKEAWAY
Think of independence requirements like layers of security at a government building. The AICPA Code is the standard lock on the front door. The GAO Yellow Book adds a security checkpoint with a guard who evaluates every potential threat. The DOL requirements are like a restricted access list that categorically bars certain people from entry. When you work in a building that has all three, you must pass through every layer—the most restrictive rule at each point determines what you can and cannot do.

Visual Explanation — Layered Independence Framework

This nested diagram illustrates how independence standards layer on top of one another. The AICPA Code forms the outermost baseline. The GAO Yellow Book applies additional restrictions when government funds are involved. The DOL rules apply the innermost and often most restrictive requirements for employee benefit plan audits. An auditor engaged on a government-sponsored employee benefit plan must comply with all three layers simultaneously.

The diagram above captures a critical concept that CPA candidates must internalize: independence standards do not operate in isolation. When an engagement falls within the jurisdiction of multiple standard-setters, the auditor must identify every applicable framework and comply with the most restrictive provision on each particular matter. A relationship that the AICPA permits might be prohibited by the GAO, and a non-audit service that the GAO allows under certain safeguards might be categorically banned under DOL interpretive guidelines. The practical implication is that engagement acceptance and continuance decisions must incorporate a multi-framework independence analysis before the first piece of audit evidence is gathered.

How the GAO Framework Operates

The Seven Threat Categories Under Government Auditing Standards

The GAO's conceptual framework identifies seven categories of threats to independence. While the AICPA framework recognizes broad threat categories, the Yellow Book is notably more granular, particularly in its treatment of management participation threats and structural threats, which are unique to the government auditing context. The seven threat categories are: (1) self-interest, (2) self-review, (3) bias, (4) familiarity, (5) undue influence, (6) management participation, and (7) structural. The auditor must evaluate whether any identified threat, individually or in combination, exceeds an acceptable level, and if so, must apply safeguards or decline the engagement.

Non-Audit Services Under the Yellow Book

One of the most testable areas on the CPA exam involves the GAO's treatment of non-audit services (NAS). The Yellow Book imposes three overarching requirements that must all be satisfied before an auditor can provide a non-audit service to an audit client: first, the service must not be expressly prohibited; second, the auditor must determine that the requirements for performing the service are met (including ensuring management takes responsibility for all decisions); and third, the auditor must document the basis for concluding that the NAS does not impair independence. The GAO is significantly more restrictive than the AICPA regarding NAS, particularly in areas such as preparing financial statements, maintaining accounting records, and performing internal audit functions. Even when a NAS is not outright prohibited, the auditor must apply the conceptual framework and evaluate whether any threat is too significant to be eliminated through safeguards.

⚠️ CRITICAL GAO REQUIREMENT
Under the Yellow Book, an auditor must document the independence consideration for every non-audit service provided to an audit client—even if the service is permitted. This documentation must include the threats identified, the safeguards applied, and the rationale for concluding that independence is not impaired. The AICPA does not impose this same level of mandatory documentation for every permitted NAS.

DOL Independence Mechanics for ERISA Plans

The Department of Labor's independence framework operates differently from the GAO's conceptual approach. Under 29 CFR § 2509.75-9 and related interpretive bulletins, the DOL defines independence using specific prohibited relationships. An accountant is deemed not independent with respect to a plan if the accountant, the firm, or certain members of the firm have a direct or material indirect financial interest in the plan, the plan sponsor, or any party in interest with respect to the plan. Notably, the DOL's definition of covered persons and entities may extend beyond the AICPA's definition, encompassing parties such as plan fiduciaries, plan trustees, and parties in interest under ERISA Section 3(14). Furthermore, the DOL considers an auditor's independence impaired if the auditor served as a plan trustee, fiduciary, or administrator during the period under audit or at the time of the audit.

Detailed Comparison — GAO vs. DOL vs. AICPA

This decision flowchart illustrates the process an auditor follows to determine which independence standards apply. Starting with the AICPA Code as a baseline, the auditor checks whether the engagement involves federal funds (triggering GAO Yellow Book requirements) and whether the entity is an ERISA employee benefit plan (triggering DOL requirements). When multiple frameworks apply, the most restrictive provision on each specific matter controls.
Comparison of Independence Requirements Across Three Frameworks
DimensionAICPA CodeGAO Yellow BookDOL (ERISA)
Threat categoriesSelf-review, advocacy, adverse interest, familiarity, undue influence, self-interest, management participationSame as AICPA plus bias and structural threats (7 total)Not organized by threat categories; uses specific prohibitions
Non-audit servicesPermitted with safeguards; management must agree to accept responsibilityMore restrictive; many services prohibited (e.g., preparing financial statements in certain cases); must document all NAS evaluationsGenerally follows AICPA with additional focus on plan-related services
Financial interestsDirect financial interests prohibited; material indirect financial interests prohibitedFollows AICPA rules plus any additional state/federal regulationsBroader scope: covers interests in plan, plan sponsor, and parties in interest under ERISA § 3(14)
Covered periodPeriod of professional engagement plus period covered by financial statementsPeriod covered by audit plus entire period of NAS performance; may include 2-year lookbackPeriod under audit and at the time of the audit engagement
Key unique featureConceptual framework with interpretations; rules on covered membersStructural threats unique to government; mandatory documentation of all NAS independence conclusionsParties in interest concept extends independence to a wider network of related entities

The table above reveals several critical distinctions for CPA exam purposes. Note that the GAO introduces structural threats—threats arising from the placement of the audit function within the reporting structure of the government entity—which have no direct parallel in the AICPA framework. Similarly, the DOL's concept of parties in interest extends the independence net much further than the AICPA's "covered member" concept, potentially encompassing employers, unions, service providers, and other entities that have a direct relationship to the benefit plan.

Worked Example — Multi-Framework Independence Analysis

Scenario: Audit of a State Government Employee Pension Plan
1
Step 1 — Identify the EngagementCPA firm Johnson & Associates has been engaged to audit the financial statements of the State of Illinois Public Employee Pension Fund for the year ended December 31. The pension fund is an employee benefit plan subject to ERISA, and the state receives federal pass-through funds, triggering Government Auditing Standards. The firm is a member of the AICPA.
Three frameworks apply: AICPA Code, GAO Yellow Book, and DOL ERISA requirements.
2
Step 2 — Identify Potential Independence ThreatsDuring the engagement acceptance process, the firm discovers the following: (a) A senior manager on the engagement team holds 50 shares of stock in ABC Asset Management, which serves as the plan's investment advisor and is a party in interest under ERISA § 3(14). (b) The firm prepared the plan's Form 5500 tax filing in the previous year. (c) A partner's spouse is employed by the state's Department of Finance, though not in a financial oversight role for the pension fund.
Three potential threats identified across self-interest, self-review, and familiarity categories.
3
Step 3 — Apply AICPA Code AnalysisUnder the AICPA Code: (a) The senior manager's stock holding in ABC Asset Management may or may not impair independence depending on whether ABC is considered an "attest client" or a "covered entity" under AICPA rules. As an investment advisor, it may not be directly covered. (b) Preparing Form 5500 is generally a permissible non-audit service under AICPA rules if management takes responsibility and the service does not involve management functions. (c) A partner's spouse in a non-oversight role at the state government would likely not impair independence under the covered-member rules.
Under AICPA alone, all three items may be permissible with proper safeguards.
4
Step 4 — Apply GAO Yellow Book AnalysisUnder the Yellow Book: (a) The GAO conceptual framework requires evaluation of the self-interest threat from the stock holding. Since the engagement involves government funds, the auditor must assess and document whether this financial interest creates an unacceptable threat. (b) Preparing the Form 5500 raises a self-review threat. Under the Yellow Book, the firm must evaluate whether preparing a key regulatory filing for the plan could impair the auditor's objectivity when auditing information derived from that filing. The Yellow Book requires documentation of the threat evaluation and safeguards applied. (c) The partner's spouse employment must be evaluated under the structural threat category for potential conflicts.
GAO imposes additional documentation requirements and may prohibit the Form 5500 preparation if adequate safeguards are not available.
5
Step 5 — Apply DOL Independence RequirementsUnder DOL regulations: (a) The senior manager's stock holding in ABC Asset Management is potentially fatal. Because ABC is a party in interest under ERISA § 3(14), the DOL considers any direct financial interest in a party in interest to impair independence—regardless of whether the amount is material under AICPA standards. The 50 shares must be divested before the engagement can proceed. (b) The Form 5500 preparation may be permissible under DOL guidance if the plan administrator takes full responsibility for the content. (c) The partner's spouse employment is evaluated under the DOL's broader relationship prohibitions and may require additional analysis.
The DOL's party-in-interest rule is the most restrictive: the stock holding that was potentially permissible under AICPA rules is categorically prohibited under DOL. The senior manager must divest the shares or be removed from the engagement.
💡 EXAM TIP
On the CPA exam, expect questions that present a scenario where the AICPA, GAO, and DOL reach different conclusions about the same relationship or service. The tested concept is almost always that the most restrictive standard governs. When analyzing multiple-choice questions, identify each applicable framework first, then apply each one separately before concluding with the most restrictive result.

Strengths, Limitations & Key Differences Among Frameworks

Strengths and Limitations of Overlapping Independence Frameworks
FeatureStrengthLimitation / Complexity
GAO Conceptual FrameworkFlexible and principles-based; applies to novel situations not anticipated by specific rules; seven threat categories provide comprehensive coverageRequires significant professional judgment; documentation burden is substantial; may lead to inconsistent application across firms
GAO NAS RestrictionsProvides clear bright-line prohibitions for the most risky services; protects public interest in government accountabilityMay require audit clients to engage separate firms for routine services, increasing costs for government entities
DOL Party-in-Interest RulesExtends the independence perimeter to capture relationships missed by AICPA rules; directly protects plan participantsThe breadth of ERISA § 3(14) means that identifying all parties in interest can be extremely complex, especially for large multiemployer plans
Multi-Framework ComplianceEnsures the highest level of independence protection when public funds and employee welfare are at stakeCreates significant compliance burden; firms must maintain expertise in multiple frameworks; potential for unintentional violations
KEY TAKEAWAY
The overlap of GAO, DOL, and AICPA frameworks is analogous to the way a company's tax obligation is determined by federal, state, and local tax codes simultaneously. Just as a corporate treasurer must identify which jurisdiction imposes the highest rate on each type of income, an auditor must identify which independence standard imposes the greatest restriction on each type of relationship, financial interest, or non-audit service. The cost of non-compliance is not merely a fee dispute—it can result in an audit opinion being deemed worthless, regulatory sanctions, and personal liability for the engagement partner.

Connections to Advanced Theory — PCAOB, IESBA & Evolving Standards

The independence requirements examined in this lesson exist within an even broader ecosystem of standard-setters. CPA candidates should understand how the GAO and DOL frameworks relate to two additional bodies: the Public Company Accounting Oversight Board (PCAOB) and the International Ethics Standards Board for Accountants (IESBA). The PCAOB's independence rules under SOX largely adopt the SEC's rules (Regulation S-X, Rule 2-01), which are themselves more restrictive than the AICPA Code for issuers. The IESBA's International Code of Ethics employs a threats-and-safeguards approach that closely mirrors the GAO's conceptual framework, reflecting the international convergence movement in auditing standards.

GAO/DOL vs. PCAOB/SEC Independence Requirements
DimensionGAO / DOL (This Lesson)PCAOB / SEC (Advanced)
ApplicabilityGovernment entities, federal fund recipients, and ERISA plansIssuers (public companies) registered with the SEC
ApproachGAO: conceptual framework + specific prohibitions; DOL: specific prohibitionsPrimarily rules-based (SEC Regulation S-X); less reliance on safeguards
Non-audit servicesGAO has extensive NAS prohibitions; DOL defers largely to AICPA with plan-specific additionsSOX § 201 categorically prohibits nine types of NAS for issuers; pre-approval by audit committee required for all others
Partner rotationNot mandated by GAO or DOL (though some government contracts require it)Mandatory partner rotation every 5 years for issuers under SOX § 203
Cooling-off periodGAO addresses employment-related cooling off through its conceptual frameworkSOX § 206 imposes a 1-year cooling-off period before audit firm personnel can accept certain positions at issuer clients

As you advance in your studies, you will encounter situations where a single audit firm may be subject to AICPA, GAO, DOL, and PCAOB rules simultaneously—for example, when a public company sponsors an ERISA-covered employee benefit plan that receives government subsidies. In such cases, the engagement team must navigate four overlapping independence frameworks, applying the most restrictive provision from each on every specific matter. This reality underscores why large audit firms invest heavily in independence compliance systems and automated monitoring tools that flag potential conflicts across all applicable standard-setters before engagement acceptance.

Practice Problems

1
Under Government Auditing Standards (the Yellow Book) issued by the GAO, the independence requirements for auditors performing government audits are generally considered to be:
2
Under GAO independence standards, which of the following nonaudit services, if provided to an audited entity, would most likely impair auditor independence?
3
A CPA firm is engaged to audit the financial statements of a state agency subject to Government Auditing Standards. A partner in the firm has a spouse who is employed by the state agency as a mid-level manager in a position that does not involve financial reporting. Under GAO independence requirements, which of the following statements is most accurate?
4
An independent CPA is engaged to audit an employee benefit plan subject to the Department of Labor (DOL) independence requirements under ERISA. The CPA's firm also provides actuarial services to the plan. The plan administrator has designated an individual with suitable skill and knowledge to oversee the actuarial services. Under DOL Rules of Conduct, which of the following is correct regarding the firm's independence?
5
A CPA firm has been engaged to perform an audit of a federally funded program in accordance with Government Auditing Standards. During the engagement, the audit team discovers that a senior manager on the engagement previously served as the program's chief financial officer and left that position 18 months ago. Under GAO independence requirements, which of the following actions should the firm take?

Lesson Summary

This lesson examined the independence requirements imposed by the Government Accountability Office (GAO) through the Yellow Book (Government Auditing Standards) and by the Department of Labor (DOL) under ERISA and 29 CFR § 2509.75-9. The GAO framework employs a threats-and-safeguards approach with seven threat categories (including unique structural and management participation threats) and imposes stringent non-audit service restrictions with mandatory documentation requirements. The DOL framework uses categorical prohibitions focused on the parties in interest concept under ERISA, extending independence requirements to a broader network of related entities than the AICPA's covered-member rules.

The foundational principle across all frameworks is that when multiple independence standards apply simultaneously, the auditor must comply with the most restrictive requirement on each specific matter. Engagement acceptance and continuance decisions must incorporate a multi-framework independence analysis that identifies every applicable standard-setter—AICPA, GAO, DOL, and potentially PCAOB/SEC—before the audit commences. Mastery of these overlapping requirements is essential for CPA candidates and practicing auditors who serve government entities and employee benefit plans.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Independence Requirements — Apply GAO And Department Of Labor Independence Requirements