2.1 AICPA Code of Professional Conduct & Conceptual Framework

Key Takeaways

  • The AICPA Code is structured into a Preface (applicable to all members) and three operational parts: Part 1 (public practice), Part 2 (members in business), and Part 3 (other members).
  • The Principles of Professional Conduct express the profession's recognition of its responsibilities to the public and establish an unbending, aspirational foundation, whereas Rules and Interpretations are enforceable.
  • The Conceptual Framework applies whenever a relationship or circumstance is not specifically addressed by an established rule, requiring CPAs to identify threats, evaluate their significance, and apply safeguards.
  • There are seven codified threats to compliance: Adverse Interest, Advocacy, Familiarity, Management Participation, Self-Interest, Self-Review, and Undue Influence.
  • Safeguards created by an attest client can never, by themselves, reduce an independence threat to an acceptable level; firm-level or regulatory safeguards must also be in place.
Last updated: September 2026

2.1 AICPA Code of Professional Conduct & Conceptual Framework

CPA Exam Focus: The AICPA Code of Professional Conduct is heavily tested in Area I of the AUD blueprint. Candidates must understand not only the specific rules of conduct, but also the structural layout of the Code, the boundary between aspirational principles and enforceable rules, and the rigorous application of the Conceptual Framework when addressing novel ethical dilemmas.


Structure of the AICPA Code of Professional Conduct

The AICPA Code of Professional Conduct was substantially restructured into a codified, intuitive format to allow practitioners to quickly navigate guidance based on their professional role. The Code is organized into a Preface and three distinct operational parts:

+-------------------------------------------------------------------------+
|                    PREFACE (Applies to ALL Members)                     |
|        Definitions, Principles of Conduct, Non-Enforceable Foundation    |
+-------------------------------------------------------------------------+
          |                                 |                             |
          v                                 v                             v
+-----------------------+       +-----------------------+       +-----------------------+
|        PART 1         |       |        PART 2         |       |        PART 3         |
|  Members in Public    |       |  Members in Business  |       |     Other Members     |
|       Practice        |       | (Industry, Gov, Edu)  |       | (Retired/Unemployed)  |
| Independence, Attest, |       | Integrity, Conflict,  |       |  Acts Discreditable   |
|  General Standards    |       | Subordination of Jdg. |       |         Only          |
+-----------------------+       +-----------------------+       +-----------------------+

The Operational Divisions

SectionScope of ApplicationKey Subjects Governed
PrefaceAll members of the AICPA (public practice, corporate, government, education, retired).Definitions, foundational principles, structure of rules, citations, and authority.
Part 1Members in Public Practice (CPAs working in accounting firms offering audit, tax, or advisory services).Independence (ET 1.200), Integrity and Objectivity (ET 1.100), General Standards (ET 1.300), Compliance with Standards (ET 1.310), Accounting Principles (ET 1.320), Acts Discreditable (ET 1.400), Contingent Fees (ET 1.510), Commissions & Referral Fees (ET 1.520), Advertising (ET 1.600), Confidential Information (ET 1.700), Form of Organization (ET 1.800).
Part 2Members in Business (CPAs employed as CFOs, controllers, internal auditors, staff accountants in commerce, industry, education, or government).Integrity and Objectivity (ET 2.100), Conflicts of Interest (ET 2.110), Subordination of Judgment (ET 2.130), General Standards (ET 2.300), Compliance with Standards (ET 2.310), Accounting Principles (ET 2.320), Acts Discreditable (ET 2.400). Note: Independence does not apply to Part 2 members.
Part 3Other Members (CPAs who are retired, between positions, or working in non-financial fields).Governed strictly by Acts Discreditable (ET 3.400) (e.g., committing felonies, failing to file personal tax returns, disclosing CPA Exam questions).

The Six Principles of Professional Conduct

The Principles of Professional Conduct (ET 0.300) provide the philosophical foundation for a CPA's professional responsibilities. They express the profession's recognition of its responsibility to the public, to clients, and to colleagues.

Critical Exam Distinction: The Principles are aspirational guideposts and are not directly enforceable in disciplinary actions. In contrast, the Rules of Conduct and their official Interpretations are mandatory and legally enforceable by state boards of accountancy and the AICPA Joint Ethics Enforcement Program (JEEP).

  1. Responsibilities (ET 0.300.020): In carrying out their responsibilities as professionals, members should exercise sensitive professional and moral judgments in all their activities.
  2. The Public Interest (ET 0.300.030): Members should accept the obligation to act in a way that will serve the public interest, honor the public trust, and demonstrate commitment to professionalism. The "public" encompasses clients, credit grantors, governments, employers, investors, the business and financial community, and others who rely on the objectivity and integrity of CPAs.
  3. Integrity (ET 0.300.040): To maintain and broaden public confidence, members should perform all professional responsibilities with the highest sense of integrity. Integrity requires a member to be honest and candid within the constraints of client confidentiality, measuring service and the public trust against personal gain.
  4. Objectivity and Independence (ET 0.300.050): A member should maintain objectivity and be free of conflicts of interest in discharging professional responsibilities. A member in public practice should be independent in fact (mind) and appearance when providing auditing and other attest services.
  5. Due Care (ET 0.300.060): A member should observe the profession's technical and ethical standards, strive continually to improve competence and the quality of services, and discharge professional responsibility to the best of the member's ability. Due care requires adequate planning, supervision, and ongoing professional skepticism.
  6. Scope and Nature of Services (ET 0.300.070): A member in public practice should observe the Principles of the Code of Professional Conduct in determining the scope and nature of services to be provided. Members must ensure they do not provide non-attest services that create insurmountable conflicts of interest or management participation threats for attest clients.

The Conceptual Framework Approach

Practitioners frequently encounter complex, emerging relationships or service arrangements that are not explicitly addressed by an established rule or interpretation in the AICPA Code. In these situations, the CPA is required to apply the Conceptual Framework Approach.

The Three-Step Decision Process

[Step 1: Identify Threats]
  Identify specific relationships or circumstances that threaten compliance with the Code.
         |
         v
[Step 2: Evaluate Significance of Threats]
  Assess whether the threat is at an "Acceptable Level" from the perspective of a 
  reasonable and informed third party.
         |
         +---> If at an Acceptable Level ----> Proceed with Engagement.
         |
         v If NOT at an Acceptable Level
[Step 3: Apply Safeguards]
  Identify and apply safeguards to eliminate threats or reduce them to an acceptable level.
         |
         +---> Threat reduced to Acceptable Level? ----> Proceed with Engagement.
         |
         v If Safeguards CANNOT reduce threat
      [DECLINE OR TERMINATE ENGAGEMENT / ELIMINATE THE THREATENING RELATIONSHIP]

The Acceptable Level Standard

An acceptable level is defined as a threshold at which a reasonable and informed third party, weighing all the specific facts and circumstances available to the member at that time, would likely conclude that the member's compliance with the rules is not compromised. This is an objective legal and professional standard, not a subjective judgment by the auditor.


The Seven Threats to Professional Compliance

The Conceptual Framework codifies threats into seven distinct categories. On the CPA Exam, questions frequently present a realistic scenario and ask candidates to classify the threat:

Codified ThreatOfficial AICPA DefinitionRealistic Practice Scenario
1. Adverse InterestThe threat that a member will not act with objectivity because the member's interests are opposed to the client's interests.The client files a lawsuit against the CPA firm alleging negligent audit performance, or the CPA firm sues the client for unpaid audit fees.
2. AdvocacyThe threat that a member will promote a client's position or opinion to the point that their objectivity or independence is compromised.The audit firm acts as an expert witness for an attest client in a lawsuit against a supplier, or the CPA promotes/underwrites the client's commercial paper or initial public offering (IPO).
3. FamiliarityThe threat that, due to a long or close relationship with a client, a member will become too sympathetic to the client's interests or too accepting of the client's work.A senior audit partner has led the audit of a private company for 18 consecutive years without rotation, or the lead audit manager's spouse is a close childhood friend of the client's CFO.
4. Management ParticipationThe threat that a member will take on the role of client management or assume management responsibilities for the attest client.The CPA firm authorizes payroll transactions, selects an ERP software system on behalf of the board, or hires executive management for the client. (Note: Cannot be mitigated by safeguards!)
5. Self-InterestThe threat that a member could benefit, financially or otherwise, from an interest in, or a relationship with, a client or persons associated with the client.The CPA firm derives 40% of its total firm-wide operating revenue from a single attest client, or the audit senior holds stock in the audit client.
6. Self-ReviewThe threat that a member will not appropriately evaluate the results of a previous judgment made, or service performed or supervised by the member or an individual in the member's firm.The CPA firm prepares the complex tax accrual or calculates the fair value of intangible assets during a consulting project and subsequently audits those exact journal entries during the annual audit.
7. Undue InfluenceThe threat that a member will subordinate their judgment to an individual associated with a client or any relevant third party due to the individual's reputation or expertise, aggressive or dominant personality, or attempts to coerce or exercise excessive influence over the member.The client's CEO aggressively threatens to fire the audit firm and switch to a competitor unless the engagement partner agrees to an aggressive revenue recognition policy.

The Hierarchy of Safeguards

Safeguards are controls that eliminate threats or reduce them to an acceptable level. Under the AICPA Conceptual Framework, safeguards fall into three categories:

  1. Safeguards created by the profession, legislation, or regulation:
    • Mandatory continuing professional education (CPE) requirements.
    • Professional standards, monitoring, and disciplinary proceedings (AICPA, state boards).
    • External peer review of the firm's quality management system.
    • Periodic regulatory inspections (e.g., PCAOB inspections).
  2. Safeguards implemented by the attest client:
    • Skilled, competent personnel who oversee non-attest services.
    • An independent, active audit committee that oversees financial reporting and auditor selection.
    • A strong corporate governance framework and ethical "tone at the top."
    • MANDATORY EXAM RULE: Safeguards implemented solely by the client can never be the only safeguards relied upon to reduce a threat to an acceptable level. Firm-level or professional safeguards are always required.
  3. Safeguards implemented by the firm:
    • Policies requiring second-partner concurring reviews (engagement quality reviews).
    • Firm policies requiring consultation with national technical experts on contentious issues.
    • Rotating key engagement personnel off the audit team after a set number of years.
    • Involving another CPA firm to re-perform or review portions of the non-attest or audit work.

Subordination of Judgment Framework (ET 1.130 & ET 2.130)

Both Part 1 and Part 2 of the Code contain an explicit, step-by-step resolution process when a CPA has a material disagreement with a supervisor regarding an accounting entry, auditing procedure, or financial statement presentation:

[Disagreement on Accounting/Auditing Matter with Supervisor]
                           |
                           v
[Step 1: Evaluate Threat Significance]
  Determine if the supervisor's position fails to comply with GAAP/GAAS, 
  creates a material misstatement, or violates professional standards.
                           |
                           v
[Step 2: Discuss with Supervisor]
  Present factual findings and professional standards to the supervisor.
                           |
             +-------------+-------------+
             |                           |
             v Position Resolved         v Position NOT Resolved
        [Document]             [Step 3: Escalate Internally]
                                 Take concerns to supervisor's superior,
                                 audit committee, or managing partner.
                                         |
                           +-------------+-------------+
                           |                           |
                           v Position Resolved         v Position NOT Resolved
                      [Document]             [Step 4: Final Safeguards]
                                               Consider legal counsel, document the
                                               issue, evaluate any duty to communicate
                                               externally, and consider whether to
                                               continue the relationship.

Common Exam Traps & Pitfalls

  • Trap 1: Believing Principles are Enforceable. Candidates often see an exam question asking which provision forms the basis of a disciplinary suspension. The answer will never be a Principle (e.g., "Article II - The Public Interest"); disciplinary actions must be cited under specific Rules (e.g., ET 1.400.001 Acts Discreditable).
  • Trap 2: Over-relying on Client Safeguards. When presented with a case where a CPA provides bookkeeping to an attest client, an option will often state: "The threat is eliminated because the client's board approved the arrangement." This is incorrect. Client-implemented safeguards can never independently reduce an independence threat to an acceptable level.
  • Trap 3: Management Participation Cannot Be Mitigated. If a CPA accepts management responsibilities (such as authorizing invoices, signing checks, or executing contracts), no safeguards exist in the profession that can reduce the threat to an acceptable level. Independence is unconditionally impaired.
Test Your Knowledge

Under the AICPA Code of Professional Conduct Conceptual Framework, which of the following situations illustrates an Adverse Interest threat to a CPA firm's independence?

A
B
C
D
Test Your Knowledge

A CPA firm is evaluating whether it may accept a non-attest consulting engagement for an existing audit client under the AICPA Conceptual Framework. The engagement partner determines that the service creates significant self-review threats, but notes that the client's audit committee has established an internal technical oversight committee to review all work. Which statement correctly evaluates this safeguard?

A
B
C
D
Test Your Knowledge

Which specific part of the AICPA Code of Professional Conduct governs a licensed CPA who works as a corporate controller for a privately owned construction company?

A
B
C
D
Test Your Knowledge

Under the AICPA Conceptual Framework, which threat arises when a member promotes an attest client's position to the extent that the member's objectivity or independence is compromised?

A
B
C
D