Auditor Qualifications for HUD Multifamily Engagements

The first thing worth establishing is that not every HUD-covered entity actually needs a full audit. But what if your entity sits close to the threshold — does the analysis change? HUD's Consolidated Audit Guide, formally Handbook 2000.04, governs audits of profit-motivated entities subject to 24 CFR Part 5, Subpart H, and 24 CFR Part 202.5(g). The covered universe includes HUD-approved lenders, mortgage-backed security issuers, and multifamily project owners. For profit-motivated multifamily projects, an audited financial statement is required when annual expenditures or HUD-insured or HUD-guaranteed loan balances reach $500,000 or more.
Below that threshold, HUD Housing Notice H2013-23 permits owner-certified financial statements. Those submissions carry no auditor's opinion and no compliance report. An owner may still engage a CPA to prepare GAAP-based financials, but the full qualification stack described throughout this piece is not triggered.
For nonprofit multifamily projects, the framework shifts entirely. Nonprofit and governmental organizations participating in HUD housing programs fall under the Single Audit Act and 2 CFR Part 200.500, commonly referred to as Subpart F, rather than the Consolidated Audit Guide. The audit threshold for nonprofit multifamily projects is $1,000,000 or more in federal expenditures for fiscal years beginning on or after October 1, 2024, raised from the prior $750,000 threshold.
This distinction matters because the compliance frameworks diverge in meaningful ways. An auditor experienced exclusively in Single Audit work may be operationally unprepared for a Consolidated Audit Guide engagement, and vice versa. Two auditors can hold identical credentials and yet be entirely unsuited for each other's work. The threshold question, then, determines not just whether an audit is required, but which regulatory architecture governs it and what auditor qualifications are actually necessary.
The foundational credential: what it means to be an "independent certified public accountant" for these engagements
Handbook 2000.04 is explicit: the audit must be conducted by an independent certified public accountant. That language is load-bearing in two directions.
The first is credential. State CPA licensure in good standing is a prerequisite, full stop. But licensure is where the requirements begin, not where they end.
The second is standards. Work performed under the Consolidated Audit Guide must conform to both Generally Accepted Auditing Standards, issued by the AICPA, and Government Auditing Standards, commonly called the Yellow Book, issued by the Comptroller General of the United States. These are not alternative frameworks; they are cumulative. GAAS alone is insufficient. The GAGAS overlay is mandatory.
There is one narrow exception: for SEC registrants, the financial statement audit component may be performed under PCAOB standards combined with GAGAS. Most HUD multifamily engagements do not involve SEC registrants.
The GAGAS requirement applies not just at the firm level but at the level of staff actually assigned to the engagement. A firm whose lead partner holds all required credentials satisfies only part of the obligation. The individuals performing fieldwork, preparing workpapers, and drafting reports must themselves meet GAGAS qualifications. This point is consistently underweighted in auditor selection conversations, and the consequences surface during REAC Quality Control Reviews.
State CPA licensure: necessary, not sufficient. GAGAS competence is the variable that separates a generalist CPA from someone actually qualified to perform these engagements, and GAGAS demands sustained, documented investment that licensure alone does not require or verify.
What Government Auditing Standards (the Yellow Book) actually require of the auditor
Chapter 1 of Handbook 2000.04 requires auditors to meet GAGAS qualifications in three domains: independence, continuing professional education, and the audit organization's quality control standards.
The CPE requirement has a specific structure. Auditors must complete 80 hours every two years, with a minimum of 20 hours in each individual year. Of the 80 total hours, 24 must be "government CPE," covering subjects such as GAGAS itself, the GAO Green Book, government accounting standards, applicable ethics, and government auditing topics including IT auditing, regulatory compliance, fraud, and risk. The remaining 56 hours have broader latitude, though they must still be relevant to the auditor's work.
There is a limited exemption from the 56-hour general component, though not from the 24-hour government requirement, for auditors who charge less than 20 percent of their time to GAGAS engagements and are not involved in planning, directing, or reporting on those engagements. In practice, that exemption is narrower than it sounds. Any auditor with a meaningful role in a HUD engagement, including a staff associate performing a substantial share of fieldwork, will typically fail to qualify.
Quality control sits alongside CPE as a distinct requirement. The audit organization itself must meet GAGAS quality control standards, and individual practitioners alone cannot satisfy this obligation. A solo practitioner or small firm with technically qualified staff may still fall short if the organization's quality control infrastructure is inadequate. Individual credentials and organizational infrastructure are two separate inquiries. Conflating them is a common source of selection errors.
The current edition governing most active engagements is the 2018 Yellow Book, which applies to periods beginning before December 15, 2025. The 2024 Yellow Book becomes effective for periods beginning on or after that date. Firms with engagements spanning the transition need to confirm, based on the specific period covered, which edition applies.
Key changes in the 2024 Yellow Book that affect auditor qualifications going forward
The most consequential structural change in the 2024 revision is a formal quality management system requirement. Audit organizations must design and implement such a system by December 15, 2025, and complete an evaluation of its operation within one year of that date. This aligns GAGAS with recent AICPA quality management standards. The system must incorporate a risk assessment process: identifying, evaluating, and mitigating risks to audit quality, with audit leadership assigned explicit responsibility for proactive quality management rather than reactive remediation.
For firms that have historically treated quality control as a checklist exercise, this is a material shift. The 2024 framework anticipates ongoing monitoring, not periodic compliance sprints. A firm that was nominally compliant under prior editions may find itself structurally unprepared under the new framework.
The 2024 Yellow Book also updates competence requirements, introducing more targeted CPE in cybersecurity, data analytics, and fraud detection. This reflects a recognition that the risk landscape for government programs has evolved and that auditor competence requirements should track that evolution.
On nonaudit services, the 2024 version requires auditors to disclose all nonaudit services performed for an audited client and evaluate each as a potential threat to independence. This is more demanding than the prior framing and has practical implications for firms that provide bookkeeping, financial statement preparation, or consulting services to entities they also audit.
It is also worth considering what the 2024 revision retained: the conceptual independence framework, the 80-hour CPE requirement with its 24-hour government component, and the three-year peer review cycle. For auditors already operating within this space, the continuity of those core requirements is as practically significant as the changes, because the foundational compliance infrastructure built under prior editions remains applicable.
How GAGAS defines and applies independence to HUD multifamily engagements
GAGAS independence does not operate through a fixed list of categorical prohibitions. It operates through a conceptual framework: the auditor identifies threats to independence, evaluates their significance, and applies safeguards sufficient to reduce those threats to an acceptable level. The framework demands active judgment rather than mechanical compliance.
In practice, nonaudit services are the most common source of independence complications. A firm that helps a client prepare financial statements, manage their accounting function, or consult on HUD regulatory matters is performing nonaudit services that must be disclosed and assessed under the 2024 Yellow Book. The concern is self-review threats and management participation threats, both named threat categories under the GAGAS conceptual framework, that impair objective judgment, not a categorical prohibition on ancillary services.
Auditor longevity raises a different set of questions. There is no mandatory rotation requirement for HUD multifamily engagements under the Consolidated Audit Guide, the Single Audit Act, or GAGAS. HUD field offices have informally suggested rotation over the years, but current professional standards treat longevity as a threat to be assessed and managed, not a per se disqualifier. A long-tenured auditor is not automatically compromised; an auditor who has never documented how longevity was evaluated as a threat is a different matter. Familiarity with a client's operations is, in some respects, an asset. But how does this affect our original promise of independent judgment? It must also be weighed openly against the risk that familiarity has dulled professional skepticism, which GAGAS treats as a foundational auditor attribute. That tension is real, and auditors who dismiss it without documentation are the ones who surface problems during oversight reviews.
Entities evaluating an auditor's independence posture should look for three things: disclosed nonaudit services, a documented threat-and-safeguards analysis, and the absence of impairments from financial or personal relationships with the entity. These should be visible in engagement files, in the management representation letter, and in the auditor's own representations, not reconstructed after the fact.
Peer review and what a satisfactory result actually signals
GAGAS requires audit organizations to undergo an external quality control review on a three-year cycle. The 2024 Yellow Book retained this requirement without modification. Under a system review, the most common peer review type for firms performing GAGAS engagements, an independent firm examines the reviewed organization's quality control system and a sample of its engagements to assess whether standards are being met.
The peer review report does not need to be submitted to HUD field offices or to HUD's Office of Inspector General as a routine filing matter, though it must be made available to appropriate oversight bodies per GAGAS. Entities selecting an auditor should ask for proof of a satisfactory result directly.
A satisfactory peer review is evidence that the firm's quality control system has been independently validated. A firm that represents strong internal quality management but has never submitted to external review is making an assertion that peer review exists specifically to test. An unsatisfactory or modified result signals systemic quality or independence issues that credentials and representations alone would not reveal. The distinction between these outcomes matters more than most selection processes treat it.
HUD's own oversight layer: the QASS system and the UII registration requirement
HUD's Real Estate Assessment Center, known as REAC, maintains a Quality Assurance Operations Division, referred to as QASS, that conducts Quality Control Reviews of IPA firms submitting work through REAC systems. The framing HUD uses is deliberate: IPA firms are considered the first line of defense in assessing the financial condition of housing entities. QASS oversight exists because the accuracy of data submitted through FASSUB, the Financial Assessment Subsystem used for multifamily housing filings, drives how HUD scores properties and identifies compliance issues. Approximately 21,000 HUD-insured and HUD-assisted multifamily properties submit audited financial statements to HUD annually. At that scale, audit quality is not an academic concern.
Registration with the QASS system is an administrative prerequisite for submitting a compliant audit package. Auditing firms must obtain a five-digit Unique IPA Identifier, the UII number, which is linked directly to the financial submission in FASSUB. A firm without a UII cannot file a compliant package. This is not a formality that can be addressed after the audit is complete.
QCRs are required once every six years, or at an interval determined by OMB, and results must be made public. HUD is required to report significant problems identified through QCRs to state licensing agencies and professional bodies. The REAC website documents cases where state CPA licenses were revoked based in part on a firm's failure to produce records for a QCR. The oversight mechanism has teeth, even if it operates quietly most of the time.
Familiarity with HUD-specific reporting and the compliance audit component
Every audit conducted under the Consolidated Audit Guide has two mandatory components: a financial statement audit performed under GAAS and GAGAS, and a compliance audit of the entity's major HUD programs performed according to procedures specified in the Guide itself.
The compliance audit procedures are program-specific. Chapters 1 and 2 of the Guide set out purpose, background, general requirements, and reporting requirements applicable to all covered audits. Each subsequent chapter addresses a specific HUD program: multifamily housing, mortgage insurance, and others. The compliance procedures for a multifamily housing audit are not the same as those for a mortgage insurance audit. The Guide is currently being released chapter by chapter as part of a consolidation effort toward a revised edition; the most recent major updates are CHG-20 and CHG-22.
What the compliance overlay demands is not just technical knowledge of the Guide's procedures. It demands practical experience applying the correct chapter to the correct program type. One might argue that broad HUD multifamily experience is sufficient preparation — but I have seen firms with satisfactory peer reviews and active UIIs apply procedures from the wrong chapter, not because they were careless, but because they had audited adjacent program types and assumed the procedures transferred. They do not transfer cleanly. This is the practical competence gap that makes relatively few CPAs actually qualified to perform these engagements.
Audited financial statements are submitted through FASSUB in accordance with HUD's Uniform Financial Reporting Standards; the auditor's opinion and compliance report travel with the financial package, and the UII links the firm to the filing. The auditor's work product is not just a deliverable to the client. It is a submission to a federal system that uses it to assess financial condition and regulatory compliance at the property level. That distinction in how the work is ultimately used shapes what preparation and experience actually require.
A practical checklist for entities selecting or evaluating a HUD multifamily auditor
The qualification stack, laid out in full, resolves into a set of concrete questions. These are worth asking before signing an engagement letter, and ideally before the scope of services is finalized.
CPA licensure in good standing. Confirm that the firm and the lead engagement partner hold an active license in the relevant jurisdiction with no disciplinary history.
Documented GAGAS compliance. Ask whether the firm performs audits under Government Auditing Standards and whether it can demonstrate CPE compliance, including the 24-hour government CPE component, for the specific staff assigned to your engagement. A firm-level representation is insufficient if the assigned staff cannot substantiate their own hours.
Satisfactory external peer review within the past three years. Ask to see the actual report. A satisfactory result means the firm's quality control system was independently validated. Anything less warrants follow-up.
Active UII registration with HUD's QASS system. Ask for the firm's UII number and confirm it is active. Without it, the firm cannot submit a compliant package to FASSUB. This is verifiable independently.
No significant QCR findings. Ask whether the firm has been subject to a QASS Quality Control Review and what the result was. Results are public. A firm that is reluctant to discuss this is worth examining more carefully.
Independence analysis. Ask how the firm handles nonaudit services for audit clients and whether it maintains a documented threat-and-safeguards process. Under the 2024 Yellow Book, all nonaudit services must be disclosed and assessed. Confirm that no financial or personal relationships exist that would impair independence.
Program-specific experience. Confirm that the auditor has worked with the specific Guide chapter or chapters applicable to your entity's program type. Broad HUD multifamily experience is not the same as experience with the precise compliance procedures governing your program.
2024 Yellow Book readiness. For engagements with periods beginning on or after December 15, 2025, confirm that the firm has its quality management system designed and implemented. This requires action in advance of the effective date, not on it.
Qualified HUD multifamily auditors are not scarce because the work is obscure. They are scarce because meeting the full standard requires sustained investment across multiple domains simultaneously, and the market rarely prices that investment transparently. Entities that treat auditor selection as primarily a fee negotiation tend to discover the cost of that approach at precisely the wrong moment: when a QCR surfaces a deficiency, when FASSUB rejects a submission for a missing UII, or when a compliance finding reveals that the auditor applied a procedure from the wrong program chapter. By then, the gap between "a CPA performed the audit" and "a qualified auditor performed the audit" is no longer a regulatory abstraction. It is a problem with a deadline attached.


