Peer Review Engagement Letter Template for the United States

Generate a bespoke document

What is a Peer Review Engagement Letter?

The Peer Review Engagement Letter is a crucial document required by the AICPA's peer review program in the United States. This letter is used when a CPA firm needs to undergo mandatory quality control review of their accounting and auditing practices, typically every three years. The document outlines the specific terms of engagement, including the type of peer review (system or engagement), scope of work, timeline, fees, and mutual responsibilities. It ensures compliance with professional standards while protecting both parties' interests. The letter must adhere to both federal requirements and state-specific regulations, making it an essential component of the peer review process.

Frequently Asked Questions

Is a Peer Review Engagement Letter legally binding under US law?

Yes, a Peer Review Engagement Letter is a legally binding contract under US law once signed by both CPA firms. It creates enforceable obligations regarding the scope of review, timelines, fees, and confidentiality requirements. Courts will enforce the terms as they would any professional services contract, making it crucial that all terms are clearly defined and agreed upon.

How does a Peer Review Engagement Letter differ from a general audit engagement letter?

A Peer Review Engagement Letter specifically governs the review of a CPA firm's quality control system and compliance with professional standards, while an audit engagement letter covers client financial statement audits. The peer review letter focuses on internal firm practices, AICPA compliance, and typically involves CPA-to-CPA relationships rather than CPA-to-client relationships.

Can my CPA firm face penalties if our Peer Review Engagement Letter is missing key terms?

Yes, incomplete engagement letters can result in AICPA sanctions, state board disciplinary action, and potential liability issues. Missing elements like scope limitations, confidentiality provisions, or fee structures can lead to disputes, failed peer reviews, and regulatory violations that may affect your firm's license to practice.

Which specific US regulations must a Peer Review Engagement Letter address?

The letter must comply with AICPA Standards for Performing and Reporting on Peer Reviews, the AICPA Code of Professional Conduct, and relevant state CPA society requirements. It should also address confidentiality under the Gramm-Leach-Bliley Act, state privacy laws, and any industry-specific regulations that apply to the reviewed firm's client base.

How long does it typically take to prepare a Peer Review Engagement Letter?

Using a template, most CPA firms can prepare a basic engagement letter within 1-2 hours. However, customizing terms for complex firm structures, multiple locations, or specialized practices may take several days. The negotiation and finalization process between reviewing and reviewed firms typically adds another 1-2 weeks to the timeline.

Can peer review engagement letters be terminated early under US law?

Yes, but termination must comply with the contract terms and AICPA requirements. Early termination without proper cause may result in regulatory violations and require finding a replacement reviewer within specified timeframes. The letter should include clear termination clauses and procedures to avoid AICPA sanctions or delayed compliance deadlines.

Why do CPA firms commonly make mistakes with liability limitation clauses in peer review letters?

Many firms fail to properly limit liability exposure or include indemnification provisions, creating potential financial risks. Common errors include unclear scope definitions, inadequate insurance requirements, and missing dispute resolution mechanisms. These oversights can lead to costly litigation if disagreements arise during or after the peer review process.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

United States

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Peer Review Engagement Letter

A Peer Review Engagement Letter is a legally binding contract that formalizes the relationship between a reviewing CPA firm and the firm being reviewed under the AICPA's mandatory peer review program. This document serves as your roadmap for navigating the complex quality control review process while ensuring compliance with professional standards and protecting both parties' legal interests.

When do you need this document?

You need a Peer Review Engagement Letter when your CPA firm is required to undergo its mandatory triennial peer review under AICPA standards. This applies whether you're conducting system reviews for firms with audit and attestation engagements or engagement reviews for firms performing only compilation, review, or preparation services. The letter is also required when you're the reviewing firm taking on peer review engagements for other practitioners. Additionally, if your firm is transitioning between different types of peer reviews due to practice changes, you'll need a new engagement letter reflecting the updated scope and requirements.

Key legal considerations

The engagement letter must clearly define the scope of work, specifying whether it's a system review or engagement review and the exact period being covered. Professional liability protection is crucial, so include clear limitations on the reviewing firm's responsibilities and potential exposure. Confidentiality provisions are essential given the sensitive nature of client information that may be reviewed, requiring compliance with the Gramm-Leach-Bliley Act and state privacy laws. Fee arrangements should be detailed to avoid disputes, including provisions for additional costs if the review scope expands. The letter should also address document retention requirements, as peer review workpapers must be maintained for specific periods under professional standards.

Legal requirements in United States

Under United States law, peer review engagement letters must comply with AICPA Standards for Performing and Reporting on Peer Reviews, which establish minimum requirements for review procedures and reporting. State CPA societies impose additional requirements that vary by jurisdiction, including specific reviewer qualifications and administrative procedures. The AICPA Code of Professional Conduct governs the ethical obligations of both parties, particularly regarding independence and objectivity. Contract law principles apply, meaning the letter must meet state-specific requirements for valid contracts, including consideration, mutual assent, and proper execution. Professional licensing regulations require that reviewing firms maintain appropriate qualifications and that reviewed firms cooperate fully with the process. State Boards of Accountancy may have specific requirements for peer review documentation and reporting that must be incorporated into the engagement terms.

GOVERNING LAW

Applicable law

This Peer Review Engagement Letter is drafted to comply with United States law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it