Can our statutory auditor be the QI reviewer?

Author: Alexander Fölsche, CPA (US), Wirtschaftsprüfer (Germany), Swiss Licensed Audit Expert

Short answer: Yes — if independence is unquestionable. The QI Agreement allows an internal or external reviewer. What is prohibited is self-review and any same-firm conflict, especially where the same firm designed, implemented, or operated the bank’s QI, FATCA or 1042-S processes.

What the reviewer’s work supports: the Responsible Officer (RO) Certification. The periodic review must be method-aligned and produce defensible evidence, including test scripts, samples, findings, remediation and dossier mapping.

1) What is actually required?

  • Independence and objectivity of the reviewer, whether internal audit or an external firm.
  • Appendix-aligned scope covering documentation, withholding and reporting.
  • Evidence-based testing, including sampling plan, test execution, findings and an RO certification dossier.

Rule of thumb: the builder or operator cannot be the reviewer.

2) Independence requirements — clear and auditable

A) No self-review

The reviewer must not evaluate work that they, or their firm, designed, implemented or operated. Examples include W-8/W-9 validation rules, coding guides, FATCA or withholding workflows, 1042-S mappings, or automation tools used in QI controls.

B) Avoid the same-firm conflict

If the statutory auditor’s firm performed QI design or operations, the firm is conflicted for the QI review, even if a different team would perform the review.

C) Internal reviewer is allowed if separated

Internal Audit, or a suitably segregated second-line function, may perform the review where it is functionally independent from QI operations, has a documented mandate and method, and receives full evidence access.

3) Typical conflict scenarios and clean solutions

Situation Conflict? Clean solution
Statutory auditor only audits financial statements No conflict May act as QI reviewer; document independence
Same firm authored W-8/W-9 rules or 1042-S mappings Conflict Engage a different external firm as reviewer
Internal Audit reviews; QI operations sit in Operations OK Keep functional separation; document mandate and method
External consultant built QI workflows and wants to review them Conflict Switch the reviewer; avoid self-review
Group shared service designed QI; subsidiary asks group auditor to review Likely conflict Use a firm with no prior design or operations role

4) Mini decision tree — yes/no

  1. Did the potential reviewer’s firm design, implement or operate QI, FATCA or 1042-S processes?
    Yes → Not permitted. No → proceed.
  2. Is the reviewer team or function organizationally independent from QI operations?
    No → Not permitted. Yes → proceed.
  3. Are method, scope, tests and evidence fully documentable?
    No → Fix method and evidence before starting. Yes → Permitted.

Tip: capture this in a short Independence Assessment Memo.

5) How to document independence — checklist

Place these in your dataroom:

  • Engagement acceptance memo confirming independence and no prior QI design or operations work.
  • Org chart and mandate, especially where Internal Audit performs the review.
  • Conflict-of-interest declarations at team and firm level.
  • Scope letter describing scope, deliverables and sampling approach.
  • Independence statement addressing self-review and same-firm conflicts explicitly.

Controls to tick:

  • [ ] Reviewer’s firm did no QI design or operations for the period in scope
  • [ ] Engagement team had no role in building the processes being tested
  • [ ] Full access to evidence: documents, payments, 1042-S/1042 and logs
  • [ ] Remote fieldwork permitted or on-site plan agreed
  • [ ] Reporting structure agreed: findings, remediation, dossier and QAAMS attachments

6) Sample wording — scope and independence

Independence
“[Firm] confirms that neither [Firm] nor any member of the engagement team has designed, implemented, or operated the Client’s QI/FATCA/1042-S processes or tools during the period under review. No self-review or same-firm conflict exists.”
Scope
“The review will cover documentation, withholding, and reporting, including 1042-S/1042 reconciliation, in line with the QI Agreement appendices. Testing is risk-based across documentation files and payments. Deliverables include a findings register, remediation roadmap, and an RO certification dossier.”

7) FAQ

Can our statutory auditor be the reviewer?
Yes — provided no self-review or same-firm conflict exists. Document independence in the acceptance memo and scope letter.
Is a different team within the same firm sufficient?
No. If the firm designed or operated QI processes, the firm is conflicted for review. Engage a different firm.
Is an internal reviewer allowed?
Yes. Internal Audit can review if functionally independent from QI operations and following an appendix-aligned method with full evidence access.
Do we need on-site fieldwork?
Not required by the IRS. A fully remote review is fine if evidence is provided through a dataroom, exports and screenshares. Local data-residency rules may still require on-site viewing.
Do we need a separate review for QDD?
Through 2026 the QDD review is suspended; certification is still required. From 2027 a full QDD review is expected, so planning should start early.
Have questions about reviewer independence?
We map your situation to the QI rules in a short call.

Related service & further reading

👉 QI Periodic Review — fixed scope

```