PBC Request Automation: A Practical Guide

Build a controlled PBC request workflow with clear statuses, reminder rules, evidence boundaries, security controls, and useful metrics.


PBC request automation should handle list administration, reminders, file routing, and status reporting. It should not decide that audit evidence is sufficient, sign off an audit procedure, or close an exception that needs professional judgment.

A useful design separates receipt, objective file checks, and reviewer acceptance. One “complete” status hides the difference.

The expansion of PBC is not uniform. The IRS calls its audit deliverables “prepared by client”, while a U.S. Department of Transportation order uses “provided by client”. This guide uses PBC for either convention.

Start with a complete request row

A request must be specific enough for the client, system, and reviewer to interpret alike. Give it a stable ID that will not change when someone sorts or inserts spreadsheet rows.

Field What belongs in it
Request ID Stable engagement-specific identifier
Request Exact schedule, document, data, or explanation needed
Purpose or audit area Why the engagement team needs it
Period Fiscal year, month, balance date, or transaction range
Format PDF, native spreadsheet, CSV, portal response, or another approved form
Required detail Accounts, entities, columns, signatures, or supporting records
Client owner Person expected to provide or coordinate the item
Firm owner Person responsible for review and follow-up
Due date Agreed date, with any approved revision recorded separately
Sensitivity and channel Data class and approved delivery location
Dependencies Requests or procedures that cannot proceed without this item
Status and reason Current state plus a machine-readable exception reason

Write each request so a new contact can understand it without searching old email. “Bank support” is vague. “December 2025 bank reconciliation and bank statement for operating account ending 4421, as separate PDFs” identifies the period, account, documents, and format.

Use statuses that describe facts

The status model should expose what happened rather than imply a conclusion.

Status Meaning Who or what may set it
Draft Request is still being prepared Engagement staff
Approved Request is ready to send Assigned approver
Sent Approved request was delivered through the named channel System after delivery confirmation
Received A response or file is linked to the request System or staff
Validation needed An objective check failed or the match is ambiguous System
In review Assigned staff member is evaluating the item Reviewer
Returned Reviewer requested a correction or replacement Reviewer
Accepted Reviewer accepted the item for the stated request Reviewer
Closed No further PBC action remains for that request Authorized engagement staff

Do not let a filename match set “Accepted.” Under PCAOB AS 1105, Audit Evidence, sufficiency concerns quantity while appropriateness concerns relevance and reliability. Auditors must also evaluate the accuracy, completeness, precision, and detail of company-produced information used as evidence. Receipt does not answer those questions.

PCAOB standards apply within PCAOB jurisdiction. For other engagements, map the workflow to the governing AICPA, IAASB, government, or local requirements.

Write automation rules as conditions and actions

Each rule needs a condition, action, stop, owner, and log record. A reminder must stop after a reply or due-date change.

Condition Automated action Stop or escalation
Approved request has not been sent Send approved template through the approved account Stop on delivery failure and alert firm owner
Sent request is approaching its due date Send the scheduled reminder Stop if received, returned, paused, or due date changed
Upload is linked to one request and passes file-level checks Set Received and notify reviewer Never set Accepted
Upload could match several requests Set Validation needed Firm owner chooses the match
Client asks an accounting or audit question Route the message with context Engagement staff replies
File arrives through an unapproved channel Preserve the event and follow the firm’s security route Do not copy it into other tools automatically

Approved reminder text should include the request ID, item, due date, upload route, and firm contact. Cap the sequence and route replies to a monitored address. Stop reminders after a dispute or extension.

Worked example

Take request PBC-REV-014 for the December 2025 reconciliation and statement described above. The controller owns the client response, an audit senior owns review, and the item is due January 12, 2026.

The portal sends the approved request. On January 10, one reminder goes out because the status is still Sent. The controller uploads two PDFs the next day. The system links them to PBC-REV-014, records the uploader and time, checks that both open, and sets Received.

The senior finds that the reconciliation belongs to another account, sets Returned with reason wrong_account, and asks for a replacement. The next upload moves through Received and In review. Only the senior can set Accepted. The timeline retains both submissions.

That history is useful operational evidence, but the tracker is not a substitute for audit documentation. PCAOB AS 1215, Audit Documentation requires documentation of procedures performed, evidence obtained, conclusions reached, who performed and reviewed the work, and the relevant dates. Configure retention and links according to the firm’s governing standards and documentation policy.

Protect the files and the request trail

Choose approved storage and delivery channels before configuring reminders. Record who can view, upload, download, reassign, accept, and close items. Apply the firm’s requirements for separate accounts, limited access, multifactor authentication, encryption, and activity logs.

CISA’s small-business MFA guidance recommends enabling MFA for email, file storage, and remote access. The FTC Safeguards Rule guide lists access controls, encryption, MFA, activity logging, testing, and service-provider oversight for covered financial institutions. It lists tax preparation firms as one example of covered entities. Coverage depends on the firm’s activities and jurisdiction, so the firm should obtain its own legal and compliance advice.

If AI classifies uploads or drafts reminder text, restrict its authority. Test it on representative files, log the model and rule version, route uncertain matches to staff, and monitor corrections after launch. NIST’s Generative AI Profile treats pre-deployment testing, human oversight, and ongoing monitoring as risk-management work.

Measure the workflow, not the reminder count

Collect a baseline from comparable completed engagements. Use fixed definitions:

on-time receipt rate = items received by the approved due date ÷ items due

first-pass acceptance rate = items accepted without a return ÷ items reviewed

reopen rate = accepted items later returned to an active status ÷ accepted items

Also record median days from Sent to Accepted, staff minutes per request, reminder touches, validation exceptions, wrong-recipient events, and unauthorized access. A high on-time receipt rate does not offset weak first-pass acceptance or a security failure.

The Document Chaser shows a bounded reminder and escalation design. The client document collection guide covers the broader collection workflow outside audit-specific PBC controls.

Methodology and limitations

This guide translates official audit-evidence, documentation, and security principles into an operating model. The sample request, states, rules, and metrics are Automutiny’s method. They are not prescribed by the cited organizations.

The right status permissions, retention period, delivery channel, and reviewer depend on the engagement, client contract, professional standards, privacy obligations, and firm policy. Automation cannot establish evidence sufficiency, authenticity, legal compliance, or engagement completion on its own. Pilot one request family under supervision, inspect every exception, and revise the rules before increasing scope.

Sources

Questions this article answers

What does PBC mean in accounting and audit?

Firms use both prepared by client and provided by client. A PBC request list records the schedules, documents, data, explanations, and other material that an engagement team asks a client to provide.

What parts of a PBC request list can be automated?

A system can create approved requests, assign owners, send routine reminders, link uploads, check objective file properties, update operational statuses, and route exceptions. Engagement staff should decide whether evidence is sufficient and appropriate.

Should received and accepted be the same PBC status?

No. Received means a file or response arrived. Accepted means the assigned reviewer concluded that it satisfies the request for the engagement's purpose. Keeping the statuses separate prevents an upload from being mistaken for completed audit work.

How should PBC automation be measured?

Track staff minutes per request, days open, on-time receipt rate, first-pass acceptance rate, reminder touches, returned items, reopened items, and unauthorized sends or access. Use the same definitions before and during the pilot.

Bring us your worst workflow.

Book the Profitable Line Audit