Article

GAO’s New FAQ on Quality Management: What It Means for Nonprofits and Their Auditors 

Updated: August 24, 2026

Published: August 24, 2026

By Han Group

Introduction

Following the issuance of the 2024 Yellow Book, audit organizations performing engagements under Government Auditing Standards were required to design and implement a system of quality management and must now prepare for its initial evaluation. It’s a significant governance shift, and it generated enough practitioner questions that the Government Accountability Office (GAO) recently published a new resource to answer them: Frequently Asked Questions: Establishing and Maintaining a System of Quality Management. 

That may sound like an internal CPA-firm matter rather than something a nonprofit needs to track. But many nonprofit organizations are on the receiving end of a Yellow Book audit precisely because they receive federal awards, pass-through funding, or state and local grants that carry Government Auditing Standards requirements. When that’s the case, the quality management practices of your audit organization can affect how audit engagements are performed and monitored, making it worthwhile to understand what GAO now expects. 

A New Layer of Self-Governance for Auditors 

A system of quality management is built around three requirements: the audit organization must set clear quality objectives, identify and assess the risks that could keep it from meeting those objectives, and design and implement responses to those risks. GAO explains that the risk assessment process is iterative and should be reviewed annually and updated as needed in response to deficiencies identified through the monitoring and remediation process and changes in the nature and circumstances of the audit organization or its engagements.

The FAQ also pushes back on a shortcut some firms might be tempted to take: borrowing another firm’s risk assessment wholesale. GAO’s guidance is direct that a risk assessment copied from a template or a peer firm, without being tailored to the organization’s own engagements and circumstances, won’t hold up.

Catching Problems Before They Compound 

A risk assessment only matters if someone checks whether it’s actually working. That’s the role of the monitoring and remediation process, which exists to provide the audit organization’s leadership with reasonable assurance that policies and procedures are well designed and operating effectively, that staff are meeting their professional obligations, and that engagements are being performed and reported on correctly. Monitoring and risk assessment are meant to reinforce each other when monitoring surfaces a problem, that finding should feed back into the risk assessment rather than being treated as a one-off fix. 

When a Second Set of Eyes Gets Involved 

The FAQ’s third focus area is engagement quality reviews, or EQRs an independent, objective look at the significant judgments and conclusions reached on an engagement, performed by an individual who is not a member of the engagement team before the report goes out.  The Yellow Book does not automatically require an EQR. Instead, the audit organization must evaluate whether an EQR would assist in responding to one or more identified quality risks.

Good to Know 

Firms already subject to the AICPA’s Statements on Quality Management Standards may be able to adopt a single system of quality management rather than maintain two separate systems, provided the additional Yellow Book requirements are incorporated.

A Deadline Worth Watching 

Audit organizations were already required to have their system of quality management designed and implemented by December 15, 2025. The next milestone is closer than it might seem: a senior-level official assigned responsibility and accountability for the system must complete its first formal evaluation by December 15, 2026 about four months from now. GAO frames the system as something requiring continual upkeep, not a project with a finish line, so the maintenance obligations don’t end once that evaluation is complete.

What It Means for Your Organization 

If your nonprofit undergoes a Single Audit or another engagement performed under Government Auditing Standards, this guidance is a good reason to check in with your audit firm. A few questions worth raising at your next audit committee meeting: Has the firm’s system of quality management been fully designed and implemented? Where does it stand on the December 2026 evaluation, and who is responsible for completing it? Does the firm also follow AICPA’s quality management standards, and if so, has it unified the two systems or is it running them separately? 

CPA firms performing Yellow Book work should treat the FAQ as a checklist against their own documented risk assessment, monitoring, and EQR practices – and confirm that risk assessment reflects their own engagements rather than a borrowed template. The full FAQ is available at www.gao.gov/assets/gao-26-108710.pdf for reference.

Final Thoughts 

A formal system of quality management is still a fairly new requirement for audit organizations working under the Yellow Book, and GAO’s FAQ fills in a lot of the practical detail that the standard itself leaves open. For nonprofit organizations, the takeaway isn’t about the mechanics of a CPA firm’s internal system so much as knowing the right questions to ask, particularly with the December 2026 evaluation deadline coming into view.

At Han Group, we work with nonprofit organizations and the auditors who serve them to navigate changing standards like these. If you have questions about your organization’s audit requirements or how this guidance may affect you,