Financial Risk Assessment Checklist
Engagement Setup and PBC
Pull the signed engagement letter and confirm the risk-assessment scope, deliverables, and out-of-scope items. Watch for scope creep — a financial risk assessment is not an audit under SSARS or AICPA attest standards, and any assurance language in the letter must be removed before fieldwork starts.
Send via Suralink, TaxDome, or SmartVault. Standard items: three years of financial statements, current-year trial balance, A/R and A/P agings, debt schedules, insurance schedule, top-customer revenue concentration, current org chart. Track receipt weekly so fieldwork doesn't extend on missing items.
Document overall materiality (typically 5% of pre-tax income or 0.5-1% of revenue, whichever is lower) and performance materiality at 50-75% of overall. Memo the rationale in the workpaper — partners will reference it during findings review.
Financial Statement Risk Review
Read the auditor's opinion, footnotes, and management letter for each year. Flag going-concern qualifications, restatements, and any change in accounting framework (cash-to-accrual, GAAP-to-IFRS).
Compute current ratio, quick ratio, debt-to-equity, interest coverage, DSO, DPO, and gross-margin trend over three years. Variance > 10% YoY without a documented driver becomes a flagged item in the findings memo.
Pull revenue by top-10 customers and spend by top-10 vendors. Any customer > 10% of revenue or vendor > 20% of spend is a concentration risk for the findings memo. Note SOC 1/SOC 2 dependency on critical service providers (payroll, hosting, payment processing).
Internal Controls Review
Ask the controller for the policy document, the date of last board review, and the named risk owner. A policy > 24 months without review counts as missing for the findings memo.
Walk the cash disbursement, payroll, and journal-entry approval flows. Document who initiates, approves, and reconciles. Common weakness in SMBs: the controller both posts and approves AJEs, with no second-set-of-eyes review.
Pull the prior-year management letter and confirm each finding has been remediated. Repeat findings (same item flagged two years in a row) escalate from significant deficiency to material weakness under AS 2201.
Provide a one-page outline the client can adopt: scope, named risk owner, escalation thresholds, board-review cadence. Reference COSO ERM framework as the basis.
Credit and Receivables Risk
Export the aging from QBO, Xero, or NetSuite as of the assessment date. Tie the aging total to the GL receivables balance — variance indicates unposted invoices, misapplied payments, or a reporting-period mismatch.
Use D&B, Experian Business, or Creditsafe. Compare the credit limit on file to the highest open-AR balance for each customer in the past 12 months. A customer carrying balances > their limit without partner approval is a flagged item.
Compare standard terms (Net 30, Net 60) against industry DSO benchmarks. If client's DSO trends 20+ days above benchmark, recommend tightening terms, early-pay discounts, or factoring.
Liquidity and Market Risk
List foreign-currency revenue and payables. Note natural hedges (matched FX inflows and outflows) vs. unhedged net exposure. For unhedged exposure > 5% of revenue, recommend a forward-contract or option program with the client's bank.
Pull the rolling 13-week forecast from Float, Dryrun, or the client's spreadsheet. Run two stress scenarios: top-customer 60-day payment delay, and 20% revenue decline. Minimum cash dipping below the line-of-credit covenant trigger goes in the findings memo.
Confirm investment policy statement (IPS) is on file and the current portfolio matches it. SMB clients commonly drift into single-bank concentration above FDIC limits — note any cash position > $250K at one institution as a finding.
Operational Risk Review
Identify processes where one person holds exclusive system access or institutional knowledge — payroll administrator, sole bank-signer, the only person who knows the QBO admin password. These are the highest-likelihood operational risks in SMBs.
Confirm RTO and RPO targets are documented and the last tabletop exercise occurred within the last 12 months. A plan that has never been tested is a finding regardless of how well-written it is.
Confirm a Written Information Security Plan exists per IRS Pub 4557 (if the client is a paid preparer) or per the FTC Safeguards Rule. Check MFA on banking, accounting, and payroll systems; verify encrypted backups; review incident-response process.
Compliance and Legal Risk
Confirm 941, 940, state withholding, and sales-tax filings are current. Pull the IRS account transcript if any uncertainty. For multi-state clients, run a 50-state revenue summary against post-Wayfair economic-nexus thresholds ($100K or 200 transactions, varies by state).
Pull the top-five customer and vendor contracts. Flag uncapped indemnification, mutual-vs-one-way clauses, and limitation-of-liability ceilings below the contract value. Tie any flagged items to the insurance coverage review.
Request the legal letter (attorney representation letter) covering pending and threatened litigation. Confirm contingent liabilities are accrued or disclosed per ASC 450 — probable + estimable goes on the balance sheet, reasonably possible goes in the footnotes.
Findings and Partner Sign-Off
Aggregate flagged items by severity: control deficiency, significant deficiency, or material weakness. Each finding includes condition, criteria, cause, effect, and recommendation. Attach supporting workpapers to the memo for the partner review.
Walk the CFO and audit-committee chair through each finding. Capture management responses inline — whether they accept, mitigate, or accept-the-risk. The response language goes verbatim in the final report.
Engagement partner reviews the final report, signs in DocuSign or the practice-management portal, and the report is delivered through the client portal. Lock the engagement file in Caseware or ProSystem fx Engagement after delivery.
For material weaknesses, schedule a 90-day remediation check-in and issue a change order extending the engagement scope. Track each finding to closure in Karbon or Canopy with a named owner and target date.
Use this template in Manifestly
- Month-End Close Checklist
- New Vendor Onboarding Checklist
- New Employee Onboarding Checklist
- Staff Offboarding Checklist
- Quarterly Bookkeeping Checklist
- Year-End Accounting Checklist
- Deal Closure Checklist
- Monthly Bookkeeping Close Checklist
- Engagement Budgeting Checklist
- Project Cost Control Checklist
- Tax Audit Documentation Checklist
- Engagement Risk Management Checklist
- Monthly Financial Close Checklist
- Contract Review Checklist
- Segregation of Duties Assessment
- Acquisition Integration Checklist
- Profitability Analysis Checklist
- Post-Merger Audit Checklist
- Financial Ratio Analysis Checklist
- M&A Due Diligence Checklist
- Legal Entity Management Checklist
- Cash Flow Analysis Checklist
- Risk Assessment Checklist
- Year-End Bookkeeping Checklist
- Year-End Tax Planning Checklist
- Monthly Financial Review Checklist
- Financial Audit Checklist
- Billing Process Checklist
- Client Engagement Closeout Checklist
- Corporate Tax Preparation Checklist
- Cost-Benefit Analysis Checklist
- SOX Compliance Checklist
- Fraud Prevention Checklist
- Weekly Bookkeeping Checklist
- Cash Application Checklist
- Daily Bookkeeping Checklist
- Internal Audit Preparation Checklist
- Customer Credit Approval Checklist
- Internal Control Procedures Checklist
- Accounts Receivable Aging Report Checklist
- Quarterly Internal Control Review Checklist
- Corporate Tax Return Preparation Checklist
- Budget Variance Analysis Checklist
- Monthly Accounting Close Checklist
- Accounts Payable Aging Report Checklist
- Client Engagement Letter Renewal
- Capital Expenditure (CapEx) Approval Checklist
- Payroll Tax Filing Checklist
- Employee Expense Reimbursement Checklist
- Annual Financial Statements Checklist
- Quarterly Payroll Tax Compliance Checklist
- Grant Accounting Checklist
- End-of-Month Sales and Revenue Reporting
- Collections Management Checklist
- Cost Accounting Checklist
- System Access Control Checklist
- Accounting Policy Update Cycle
- Financial Analysis Checklist
- New Client Onboarding Checklist
- Firm Insurance Renewal Checklist
- Cash Flow Management Checklist
- Payroll Services Checklist
- New Employee Onboarding Checklist (Accounting Department)
- Business Tax Compliance Checklist
- Employee Expense Policy Compliance Checklist
- Credit and Collections Checklist
- Regulatory Compliance Checklist
- External Audit Preparation Checklist
- Investment Reconciliation Checklist
- Monthly Management Reports Checklist
- Annual Budget Preparation Checklist
- Accounts Payable Ledger Checklist
- AP Payment Processing Checklist
- Merger and Acquisition Due Diligence Checklist
- Lease Accounting Checklist
- Journal Entry Checklist
- Chart of Accounts Maintenance Checklist
- Payroll Processing Checklist
- Accounting Department Workflow Optimization
- Financial Reporting Checklist
- New Business Structuring Checklist
- Audit Preparation Checklist
- Accounts Payable Checklist
- Financial Project Planning Checklist
- Yearly Accounting Department Goals Setting
- Consulting and Advisory Services Checklist
- Account Reconciliation Checklist
- Chart of Accounts Review Checklist
- Tax Planning Checklist
- Fixed Assets Audit Checklist
- Vendor Setup and Maintenance Checklist
- Client Onboarding Checklist
- Individual Tax Return Preparation Checklist
- Employee Termination Checklist (Accounting Department)
- Cash Flow Analysis Checklist
- Risk Management Checklist
- Expense Reporting and Reimbursement Checklist
- Monthly Close Process
- Business Valuation Checklist
- Bank Reconciliation Checklist
- Sales Tax Reporting Checklist
- Internal Controls Review Checklist
- Budgeting and Forecasting Checklist
- Financial Statement Audit Checklist
- Accounting Standards Update Adoption Checklist
- Monthly Bookkeeping and Accounting Close
- Business Succession Planning
- Financial Statement Preparation Checklist
- Inventory Accounting Close Checklist
- Accounts Receivable Checklist
- Monthly Financial Reporting Checklist
- Quarterly Financial Reporting Checklist
- Performance Review Checklist (Accounting Staff)
- Vendor Contract Negotiation Checklist
- Accounting Software Migration Checklist
- Quarterly Budget Review Checklist
- Debt Management Checklist
- Fixed Assets Management Checklist
- Loan Covenant Compliance Checklist
- Accounting Software Implementation Checklist
- Cash Management Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
