Risk Management Checklist
Risk Identification
Open the prior-quarter risk register from the firm shared drive or Karbon. Carry forward any open items, note which mitigations were closed, and flag any risks where the residual score changed materially since last review.
Walk the active client list against the AICPA Code independence rules. Flag any attest client where the firm is also performing bookkeeping, payroll, or management-decision work — that's the most common SSARS / state-board breach in cross-selling firms.
Review tax-prep workflow against Circular 230 §10.34 (positions on returns), §10.21 (knowledge of error), and §10.36 (firm procedures). Note any preparer without a current PTIN, any return positions taken without documented substantial authority, and any client who hasn't responded to a §10.21 follow-up.
Cross-check current practice against IRS Pub 4557 / Pub 5708 and the FTC Safeguards Rule. Confirm the WISP exists, is dated within the last 12 months, and that MFA is enforced on TaxDome, SmartVault, UltraTax, QBO Accountant, and email. Note any laptop without disk encryption.
Capture capacity risks heading into the next deadline cycle: PTO conflicts during March 15 / April 15, single-points-of-failure on K-1 prep or sales-tax filings, and CPE shortfalls that would block license renewal.
Each row: risk description, category (engagement / regulatory / data security / operational / financial), affected client or process, current control, and owner. Attach the populated register below.
Risk Analysis and Scoring
Use the firm's 1–5 scale on both axes. For impact, anchor to dollar consequence where possible: penalty exposure, fee write-off, license action, breach-notification cost. Don't anchor to vague language like 'significant' — that's how risks score the same year over year.
For each control listed in the register, walk one current example: was the engagement letter signed before fieldwork started, was the partner review note cleared before delivery, was the deposit schedule met for the last 941 cycle. A control that exists on paper but isn't operating is a finding.
Residual = inherent score adjusted for control effectiveness. Anything residual ≥ 15 (on a 25-point scale) goes to the high-risk list and requires a named mitigation owner. Document the rationale next to each score.
Pick the tier of the most severe residual risk on the register this quarter. This drives whether the workflow continues into mitigation planning and partner escalation, or stops at routine monitoring.
Risk Mitigation Planning
Each high or critical residual risk needs a specific action, owner, and target date. Vague entries like 'improve documentation' aren't mitigations. Concrete mitigation looks like: 'Resign as bookkeeper on Client X before Q3 review engagement begins; reassign to Firm Y by Aug 1.'
Owner is a named person, not a role. Tax Partner owns Circular 230 items; Practice Coordinator owns engagement-letter and PBC items; IT lead or MSP owns WISP / Safeguards items. Target dates land before the next quarterly review, not 'ongoing.'
Pub 5708 expects the WISP to be reviewed at least annually and after any material change. If this quarter surfaced a new tool, a new staff role with client-data access, or a near-miss, revise the WISP and re-circulate for staff acknowledgment.
Critical-tier items don't wait for the quarterly review meeting. Walk the managing partner through the risk, the proposed mitigation, and any client-resignation or insurance-notification implications within two business days. Document the conversation.
Communication and Training
Cover what changed since last quarter, who owns the new mitigations, and any process changes staff need to follow — new MFA requirement, new engagement-letter template, revised PBC tracker.
Each staff member with client-data access signs the current WISP and the data-handling policy. Capture the signed acknowledgment file — auditors and insurers ask for this on every cyber renewal.
Most malpractice policies require notification of circumstances that could give rise to a claim, not just claims themselves. If the quarter surfaced a missed filing, an independence breach, or a data incident, notify the carrier in writing this week — late notice voids coverage.
Partner Review and Sign-Off
Working session with managing partner, tax partner, and audit partner if applicable. Walk the register, the residual scores, and the open mitigations. Decide which risks roll forward, which close, and which require client-level action.
Mark closed items with closure date and evidence. Add new items the partners surfaced. Reset target dates that slipped, and note the rationale — repeated slippage is itself a finding for next quarter.
Use this template in Manifestly
- Monthly Close Process
- Budgeting and Forecasting Checklist
- Monthly Bookkeeping and Accounting Close
- Financial Statement Audit Checklist
- Business Succession Planning
- Expense Reporting and Reimbursement Checklist
- Bank Reconciliation Checklist
- Fixed Assets Management Checklist
- Client Onboarding Checklist
- Accounts Receivable Checklist
- Cash Flow Analysis Checklist
- Consulting and Advisory Services Checklist
- Accounts Payable Checklist
- Tax Planning Checklist
- Account Reconciliation Checklist
- Audit Preparation Checklist
- Financial Reporting Checklist
- Business Valuation Checklist
- Payroll Processing Checklist
- Internal Controls Review Checklist
- New Business Structuring Checklist
- Chart of Accounts Maintenance Checklist
- Debt Management Checklist
- Journal Entry Checklist
- Lease Accounting Checklist
- Investment Reconciliation Checklist
- Regulatory Compliance Checklist
- Credit and Collections Checklist
- Loan Covenant Compliance Checklist
- Individual Tax Return Preparation Checklist
- Business Tax Compliance Checklist
- Cash Flow Management Checklist
- New Employee Onboarding Checklist (Accounting Department)
- New Client Onboarding Checklist
- Financial Analysis Checklist
- Employee Termination Checklist (Accounting Department)
- Employee Expense Policy Compliance Checklist
- Cost Accounting Checklist
- Accounting Policy Update Cycle
- Inventory Accounting Close Checklist
- Quarterly Budget Review Checklist
- Quarterly Internal Control Review Checklist
- Client Engagement Letter Renewal
- End-of-Month Sales and Revenue Reporting
- Capital Expenditure (CapEx) Approval Checklist
- Grant Accounting Checklist
- Performance Review Checklist (Accounting Staff)
- Accounting Software Migration Checklist
- Financial Statement Preparation Checklist
- Yearly Accounting Department Goals Setting
- Quarterly Financial Reporting Checklist
- Vendor Contract Negotiation Checklist
- Chart of Accounts Review Checklist
- Fixed Assets Audit Checklist
- Accounting Standards Update Adoption Checklist
- Sales Tax Reporting Checklist
- Merger and Acquisition Due Diligence Checklist
- Monthly Management Reports Checklist
- Financial Risk Assessment Checklist
- Firm Insurance Renewal Checklist
- Payroll Services Checklist
- Accounts Payable Ledger Checklist
- Collections Management Checklist
- Quarterly Payroll Tax Compliance Checklist
- AP Payment Processing Checklist
- Vendor Setup and Maintenance Checklist
- Employee Expense Reimbursement Checklist
- Monthly Accounting Close Checklist
- Annual Financial Statements Checklist
- Accounting Department Workflow Optimization
- Accounts Payable Aging Report Checklist
- Payroll Tax Filing Checklist
- Corporate Tax Return Preparation Checklist
- Internal Audit Preparation Checklist
- Internal Control Procedures Checklist
- External Audit Preparation Checklist
- Daily Bookkeeping Checklist
- Customer Credit Approval Checklist
- Accounts Receivable Aging Report Checklist
- Budget Variance Analysis Checklist
- Cash Application Checklist
- Financial Audit Checklist
- Cost-Benefit Analysis Checklist
- Weekly Bookkeeping Checklist
- Client Engagement Closeout Checklist
- Corporate Tax Preparation Checklist
- Year-End Bookkeeping Checklist
- Billing Process Checklist
- Risk Assessment Checklist
- Cash Flow Analysis Checklist
- Legal Entity Management Checklist
- Monthly Financial Review Checklist
- M&A Due Diligence Checklist
- Post-Merger Audit Checklist
- Profitability Analysis Checklist
- Acquisition Integration Checklist
- Year-End Tax Planning Checklist
- Segregation of Duties Assessment
- Fraud Prevention Checklist
- Cash Management Checklist
- Financial Project Planning Checklist
- System Access Control Checklist
- SOX Compliance Checklist
- Financial Ratio Analysis Checklist
- Accounting Software Implementation Checklist
- Monthly Bookkeeping Close Checklist
- Tax Audit Documentation Checklist
- Contract Review Checklist
- Project Cost Control Checklist
- Deal Closure Checklist
- Engagement Risk Management Checklist
- Year-End Accounting Checklist
- Quarterly Bookkeeping Checklist
- Staff Offboarding Checklist
- Engagement Budgeting Checklist
- Monthly Financial Reporting Checklist
- Monthly Financial Close Checklist
- New Vendor Onboarding Checklist
- Annual Budget Preparation Checklist
- New Employee Onboarding Checklist
- Month-End Close Checklist
- Firm Insurance Renewal Checklist
- Treasury Risk Assessment Checklist
- Engagement Risk Management Checklist
- Annual Insurance Review Checklist
- Software Project Risk Management Checklist
- Engagement Risk Management Checklist
- Risk Management Checklist
- Risk Mitigation Checklist
- Enterprise Risk Assessment Checklist
- Quarterly Risk Monitoring Checklist
- Law Firm Risk Management Checklist
- Business Continuity Planning Checklist
- Law Firm Risk Management Checklist
- Annual Risk Assessment Checklist
- E-commerce Risk Management Checklist
- Annual Risk Management Review Checklist
- Business Continuity Planning Checklist
- Agency Compliance and Risk Management Checklist
- School Site Risk Management Checklist
- Restaurant Insurance Review Checklist
- Market Risk Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
