What it means
The body has existed in some form since the late nineteenth century and now represents hundreds of thousands of members. Its core role is to define what competent, ethical professional work looks like, through the Code of Professional Conduct and, for private company engagements, the Statements on Auditing Standards.
Membership is voluntary, but the standards themselves are widely written into state licensing rules. Its most visible function for anyone entering the profession is the CPA examination.
The AICPA develops and grades the exam, while the individual state boards of accountancy grant the licence, set the experience requirements and hold the power to discipline. That split explains why the exam is uniform across the country while the requirements for holding a licence are not.
Understanding where its authority stops is important in a business context. Accounting standards for US financial statements come from the Financial Accounting Standards Board, and auditing standards for listed companies come from the Public Company Accounting Oversight Board, which was created by legislation after the accounting scandals of the early 2000s.
The AICPA's auditing standards therefore govern the audit of private companies, not public ones. Beyond standards, the body performs a large amount of practical work that keeps smaller firms functioning.
It runs a peer review programme in which accounting firms examine each other's quality control, publishes audit and accounting guides for specific industries, and issues technical questions and answers on awkward situations. For a small practice, this material is often the only detailed guidance available.
There is one more area worth knowing about. The AICPA maintains the Statements on Standards for Attestation Engagements, which underpin the SOC reports that technology companies routinely supply to enterprise customers as evidence of their controls.
Many business people encounter the organisation's work through a SOC 2 report long before they encounter it through an audit.
In practice
Real-world examples.
Example
A privately held manufacturer being audited for the first time is told the engagement will follow the AICPA's auditing standards rather than the public company rules. That distinction affects the documentation required, the wording of the audit report and the fee, all of which surprise a finance director who has only worked in listed companies.
Example
A software company selling to banks is asked for a SOC 2 report before a contract can be signed. The report is prepared under an AICPA attestation standard, and the company has to engage a CPA firm to test its controls over several months before the enterprise deal can close.
Example
A five partner accounting firm undergoes its triennial peer review, in which reviewers from another firm examine a sample of engagements and the firm's quality control system. A finding on insufficient documentation of audit judgements leads the firm to change its working paper templates rather than its conclusions.
Think of it
“AICPA is the professional organization for CPAs-sets standards and guidance.
Case study
Seen in the real world.
This is an illustrative and entirely fictional account. Merrow Analytics, an invented data platform business with $9,000,000 of revenue, lost two large financial services deals in the same quarter because it could not produce a SOC 2 report. The founders had assumed that a completed security questionnaire would satisfy procurement, and only discovered otherwise when both prospects asked for an independent attestation performed under professional standards.
Getting there took nine months in this fictional scenario. The company spent roughly $140,000 on readiness work, control remediation and the eventual examination fee, and had to formalise access reviews, change management and vendor oversight that had previously been handled informally. The CPA firm conducting the engagement worked to the attestation standards the AICPA maintains, which set out what evidence the examiner had to gather and what the resulting report could claim.
The founders described the exercise afterwards as expensive but clarifying. The controls they had been forced to document became a genuine operational improvement, and the report itself turned into a sales asset that shortened procurement cycles with every subsequent enterprise customer.
Watch out
Common mistakes.
- Assuming the AICPA is a government regulator with power to revoke a licence, when licensing and discipline sit with individual state boards of accountancy.
- Believing the AICPA writes US accounting standards, when financial reporting rules come from the Financial Accounting Standards Board.
- Treating AICPA auditing standards as applying to listed company audits, which are governed by the Public Company Accounting Oversight Board instead.
Questions
People also ask.
Does someone need AICPA membership to be a CPA?
No, the licence comes from a state board, and membership of the institute is a voluntary professional choice that brings resources, ethics obligations and standing.
Why do technology companies keep mentioning the AICPA?
Because SOC 1, SOC 2 and SOC 3 reports are produced under attestation standards the institute maintains, and enterprise buyers routinely require them.
Is the AICPA relevant outside the United States?
Indirectly, since its standards apply to US engagements, though multinational groups often encounter them when a US subsidiary is audited or when a US customer requests a SOC report.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%
