CPA Canada PEP Assurance Elective Cheat Sheet

Cheat sheet: CPA Canada PEP Assurance Elective reference for audit planning, risk, materiality, procedures, reporting, reviews, and assurance case writing.

Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context

Assurance Case Triage

Case cueWhat to do quickly
“Audit planning,” “year-end audit,” “financial statements”Address acceptance/continuance, independence, users, materiality, RMM, significant risks, audit approach, procedures, reporting.
“Review engagement”Emphasize limited assurance, inquiry and analytical procedures, plausibility, negative conclusion, and follow-up procedures for unusual items.
“Compilation”No assurance. Focus on whether information is compiled from management-provided records and whether the basis of accounting is described.
“Special report,” “compliance,” “non-financial information”Identify subject matter, responsible party, suitable criteria, users, assurance level, and whether direct or attestation engagement fits.
“Internal controls”State weakness, implication/risk, recommendation, and benefit. Link to assertion or business risk.
“Issue with accounting treatment”Quantify misstatement if possible, assess materiality/pervasiveness, propose audit procedures, and conclude on report effect.
“Independence/ethics concern”Identify threat, significance, safeguards, and whether decline/resignation is required if threat cannot be reduced.

Engagement Selection Matrix

Engagement / standard familyAssurance levelTypical useMain evidence styleReport conclusion styleCommon exam trap
Audit of financial statements - CASReasonableHistorical financial statementsRisk assessment, controls if relied on, substantive procedures, confirmations, inspection, recalculation, observationPositive opinion: whether FS are presented fairly, in all material respectsWriting only generic procedures without assertion, population, source, or purpose.
Review of historical financial statements - CSRE 2400LimitedPrivate company FS where audit not requiredInquiry, analytical procedures, targeted follow-upNegative form: nothing has come to attention causing belief FS are not prepared appropriatelyOver-auditing with confirmations/counts as default; review work is narrower unless concerns arise.
Compilation - CSRS 4200NoneManagement needs compiled financial informationCompile from management information; no verification unless information appears misleadingNo assurance; report describes compiled financial information and basisCalling it “low assurance.” It is no assurance.
Agreed-upon procedures - CSRS 4400NoneUsers specify procedures and receive factual findingsPerform only agreed proceduresFindings only; users draw conclusionsGiving an assurance conclusion.
Attestation engagement - CSAE 3000Reasonable or limitedAnother party measures/evaluates subject matter against criteriaEvidence on subject matter informationOpinion/conclusion on subject matter informationMissing the responsible party’s measurement/evaluation role.
Direct engagement - CSAE 3001Reasonable or limitedPractitioner evaluates subject matter directly against criteriaPractitioner performs evaluationOpinion/conclusion on outcome of practitioner’s evaluationConfusing direct with attestation.
Compliance engagements - CSAE 3530 / 3531Reasonable or limitedCompliance with agreement, regulation, policy, grant termsEvidence against compliance criteriaAttestation or direct compliance conclusionNot defining the exact compliance criteria.
Special purpose FS - CAS 800ReasonableFinancial statements prepared under special purpose frameworkAudit procedures adapted to frameworkAudit opinion with special purpose contextNot considering restricted users or framework acceptability.
Single statement/specific element - CAS 805ReasonableAudit of one statement, account, or elementAudit evidence for specific subjectOpinion on specific statement/elementIgnoring interrelationship with full FS audit.
Summary financial statements - CAS 810Reasonable on consistencySummary FS derived from audited FSCompare summary to audited FSOpinion on consistency with audited FSTreating summary FS as a full audit.

Assurance Levels and Evidence

ConceptAuditReviewCompilation / AUP
AssuranceReasonable, high but not absoluteLimitedNone
Primary workRisk-based audit evidenceInquiry and analytics, follow-upCompile information or perform specified procedures
Detection objectiveReduce audit risk to acceptably low levelIdentify whether information appears plausibleNo assurance objective
ProceduresInspection, observation, confirmation, recalculation, reperformance, analytics, inquiryInquiry, analytics, limited additional proceduresCompilation: organize info. AUP: listed procedures only
ConclusionPositive opinionNegative assurance conclusionNo conclusion on fairness
Notes and examples

Evidence Quality Hierarchy

Stronger evidenceWeaker evidence
External evidence received directly by auditorEvidence prepared internally by client
Original documentsCopies or screenshots
Written evidenceOral representations
Auditor recalculation/reperformanceClient explanation only
Evidence from effective controlsEvidence from weak control environment
Year-end evidence for balancesInterim evidence without roll-forward

Inquiry alone is rarely sufficient for an audit conclusion. Written representations support other evidence but do not replace necessary procedures.

Acceptance, Continuance, and Engagement Terms

AreaHigh-yield checks
Client integrityReputation, management honesty, fraud history, aggressive accounting, disputes with predecessor accountant.
IndependenceFinancial interests, loans, unpaid fees, close relationships, bookkeeping, management decisions, advocacy, contingent fees, gifts, employment ties.
Competence and resourcesIndustry knowledge, deadline feasibility, specialist needs, engagement team capacity.
PreconditionsAcceptable financial reporting framework, management acknowledges responsibilities, access to information and personnel.
Scope limitationIf management restricts access before acceptance, consider declining.
Engagement letterObjective, scope, responsibilities, framework, report form, inherent limitations, access, timing, fees.
Predecessor communicationObtain permission from prospective client; inquire about reasons for change, disagreements, integrity concerns.
Quality managementEnsure appropriate review, consultation, and documentation for significant judgements.
Notes and examples

Independence Threats

ThreatExampleResponse
Self-interestPartner owns shares in audit client; significant overdue feesRemove interest, collect fees, add safeguards, or decline.
Self-reviewFirm prepared accounting records then audits themUse separate team and review safeguards if allowed; avoid management decisions.
AdvocacyFirm promotes client financing or litigation positionDecline advocacy role or assurance engagement if threat too high.
FamiliarityLong association, family relationship with CFORotate personnel, independent review, remove affected person.
IntimidationManagement threatens dismissal over proposed adjustmentEscalate to governance, document, consider withdrawal.

Materiality Reference

Materiality is based on user decisions, not only a calculation. In cases, state the benchmark, justify it using users and circumstances, calculate a preliminary amount if data permits, and apply qualitative factors.

\[ \text{Overall Materiality} = \text{Selected Benchmark} \times \text{Justified Percentage} \]\[ \text{Performance Materiality} < \text{Overall Materiality} \]

Common Benchmark Heuristics

These are practical exam heuristics, not fixed rules. Justify using the case facts.

Entity / user focusPossible benchmarkWhy it may fit
Stable profitable companyNormalized income before taxUsers focus on earnings.
Break-even or volatile earningsRevenue, gross profit, assets, or equityProfit is not a stable benchmark.
Lender-focused entityAssets, EBITDA, debt covenants, incomeBank cares about solvency, coverage, covenant compliance.
Not-for-profitExpenses, revenue, assets, restricted contributionsUsers care about stewardship and use of funds.
Asset-heavy entityTotal assets or net assetsBalance sheet drives decisions.
Owner-managed private companyIncome, normalized compensation, cash flow, debt covenantsUsers may be owners, lenders, tax authorities, or buyers.

Qualitative Materiality Triggers

Small amount may still be material if it…
Turns profit into loss or affects bonus/compensation.
Causes covenant breach or regulatory non-compliance.
Masks fraud, related-party transactions, or illegal acts.
Affects key ratios, going-concern assessment, or financing.
Changes trend, segment result, or management forecast.
Involves sensitive disclosures, restrictions, or stewardship.

Audit Risk Model and Responses

\[ \text{Audit Risk} = \text{Risk of Material Misstatement} \times \text{Detection Risk} \]\[ \text{Risk of Material Misstatement} = \text{Inherent Risk} \times \text{Control Risk} \]
Risk factorEffect on audit work
Higher inherent riskMore experienced staff, more persuasive evidence, targeted procedures.
Weak controlsLess reliance on controls, more substantive testing, larger samples, year-end testing.
High fraud riskUnpredictable procedures, journal entry testing, management override work, professional skepticism.
Complex estimatesTest assumptions, methods, data, bias, sensitivity, and subsequent outcomes.
Related partiesSearch for undisclosed relationships, inspect minutes/contracts, confirm terms, assess disclosure.
Going-concern uncertaintyCash flow analysis, financing, covenants, plans, subsequent events, disclosure adequacy.
Notes and examples

Significant Risk Indicators

IndicatorWhy it mattersTypical response
Revenue pressureFraud risk in revenue recognitionCutoff testing, contract review, analytics, confirmations, journal entry testing.
Management bonus tied to EBITDABias in estimates/accrualsTest accruals, estimates, classification, unusual entries.
New system implementationCompleteness/accuracy riskIT controls, reconciliations, conversion testing, parallel runs.
Rapid growthCutoff, collectability, inventory, controls may lagExpand substantive work, test controls before reliance.
Debt covenant pressureClassification and measurement biasRecalculate covenants, inspect waivers, assess going concern.
First-year auditOpening balances and understanding entityExtra planning, predecessor review if permitted, opening balance procedures.

Assertions and Procedure Design

A strong procedure states: action + population/source + assertion + criterion + follow-up.

AssertionMeaningStrong procedure examples
Existence / occurrenceRecorded asset, liability, or transaction exists/occurredConfirm receivables directly with customers; inspect subsequent cash receipts; observe inventory count.
CompletenessAll items that should be recorded are recordedTrace receiving reports to payables; search subsequent disbursements for unrecorded liabilities.
Accuracy / valuationAmounts are recorded correctlyRecalculate depreciation; test inventory NRV; evaluate allowance assumptions.
Rights and obligationsEntity owns asset or owes liabilityInspect title, lease, debt, consignment, or security agreements.
CutoffTransactions recorded in correct periodTest shipping/receiving documents around year-end to invoices and GL.
ClassificationRecorded in proper account/current vs non-currentInspect agreements; assess debt covenant breaches and waiver timing.
Presentation / disclosureDisclosures are complete and understandableCompare FS disclosure to framework requirements and underlying agreements.
Notes and examples

Weak vs Strong Procedure Wording

Weak wordingStronger exam-ready wording
“Review revenue.”Select a sample of sales recorded five business days before and after year end; agree invoice date, shipping document, contract terms, and GL posting to assess revenue cutoff.
“Check receivables.”Send positive confirmations to a sample of material and overdue customers; for non-replies, inspect subsequent cash receipts and supporting invoices.
“Look at inventory.”Attend the year-end inventory count, perform test counts from floor to count sheet and count sheet to floor, and investigate variances.
“Discuss with management.”Inquire of management about obsolete inventory indicators and corroborate by inspecting aged inventory reports, post-year-end sales, and markdowns.

Assertion-to-Procedure Quick Map

A strong assurance answer links the risk to an assertion and then to a procedure.

Account / AreaCommon Assertion RiskStrong Procedure Examples
RevenueOccurrence, cutoff, accuracySelect sales near year-end and trace to shipping documents, contracts, invoices, and subsequent cash receipt
Accounts receivableExistence, valuationConfirm balances; review subsequent collections; assess allowance using aging and customer history
InventoryExistence, valuation, completenessAttend count; perform test counts; inspect obsolete items; compare cost to net realizable value
Purchases/payablesCompleteness, cutoffSearch for unrecorded liabilities using subsequent payments, unmatched receiving reports, supplier statements
PayrollOccurrence, accuracyReconcile payroll register to GL; test employee master file changes; inspect approvals
Fixed assetsExistence, valuation, rightsPhysically inspect additions; agree to invoices; assess capitalization vs expense; review impairment indicators
DebtCompleteness, classification, presentationConfirm with lenders; inspect agreements; test covenant compliance; review current/non-current classification
EstimatesValuation, disclosureEvaluate method, assumptions, source data, bias, subsequent events, expert reports
Related partiesCompleteness, disclosureReview minutes, confirmations, management representations, unusual transactions, ownership records
Provisions/contingenciesCompleteness, valuationLegal letter, board minutes, correspondence, subsequent payments, management assessment

Account Area Procedure Reference

AreaMain risksHigh-yield procedures
RevenueOccurrence, cutoff, completeness, fraudReview contracts; test cutoff around year-end; agree invoices to shipping/service evidence; perform trend/margin analytics; test credit notes after year-end; inspect unusual manual journal entries.
ReceivablesExistence, valuation, collectabilityConfirm balances; inspect subsequent receipts; review aging; test allowance assumptions; evaluate disputed/related-party balances.
InventoryExistence, completeness, valuation, cutoffObserve count; test count controls; perform floor-to-sheet and sheet-to-floor counts; test costing; compare cost to NRV; review obsolete/slow-moving items; test purchases/sales cutoff.
Purchases and payablesCompleteness, cutoffSearch subsequent disbursements; trace receiving reports to AP; inspect unmatched receiving reports; review supplier statements; test accruals.
PayrollOccurrence, accuracy, authorizationReconcile payroll register to GL; test new hires/terminations; agree pay rates to approved HR records; test time approval; review unusual bonuses.
CashExistence, completeness, restrictionObtain bank confirmations; reconcile bank statements; test outstanding cheques/deposits; inspect debt restrictions or compensating balances.
PPEExistence, rights, valuation, depreciationInspect additions; agree to invoices/approvals; verify title; recalculate depreciation; review impairment indicators; test disposals.
DebtCompleteness, classification, disclosureConfirm with lenders; inspect agreements; recalculate interest; test covenant compliance; assess current/non-current classification and waivers.
EstimatesValuation, biasEvaluate method, assumptions, data reliability, management bias, sensitivity, and subsequent events.
Provisions/contingenciesCompleteness, valuation, disclosureSend legal letters; inspect minutes; inquire of management/legal counsel; review post-year-end payments; assess recognition vs disclosure.
Related partiesCompleteness, measurement, disclosureInspect minutes, shareholder records, contracts, unusual transactions; confirm terms; evaluate business purpose and disclosure.
Going concernValuation, classification, disclosureEvaluate cash flow forecasts, financing, covenants, management plans, subsequent results, and disclosure adequacy.

Internal Control Reference

Control Objective Matrix

ObjectiveControl examplesEvidence to test
AuthorizationCredit approval, purchase approval, payroll change approvalApproved forms, system logs, sign-offs.
CompletenessSequential invoices, receiving report matching, bank reconciliationsSequence checks, reconciliation review evidence.
AccuracyPrice master controls, recalculation, automated edit checksException reports, recalculation, IT control logs.
Segregation of dutiesSeparate custody, recording, authorization, reconciliationRole listings, access rights, observed process.
Safeguarding assetsLocked inventory, restricted cash access, dual signingAccess logs, physical inspection, policy compliance.
Review and monitoringVariance analysis, management review, board oversightDated review notes, investigation evidence.
Notes and examples

Common Weaknesses and Recommendations

CycleWeaknessRisk / implicationBetter recommendation
RevenueSame person approves credit, records sale, and handles cashFictitious sales or stolen receiptsSeparate cash handling from recording; require independent monthly AR reconciliation review.
PurchasesVendor master changes not reviewedFictitious vendors or unauthorized paymentsRestrict vendor setup access and require independent approval of new/changed vendors.
PayrollHR changes entered without approvalGhost employees or incorrect payRequire approved HR forms and independent review of payroll change reports.
InventoryNo independent count supervisionTheft or inaccurate inventoryAssign independent count teams, use pre-numbered count sheets, investigate variances.
ITShared admin passwordsNo accountability and unauthorized changesUnique user IDs, least privilege access, periodic access review.
Financial closeManual journals posted without reviewManagement override or errorsRequire independent review of manual journals, especially unusual or late entries.

Control Testing Rules

If the case asks…Answer focus
“Can we rely on controls?”Test design and implementation first; then operating effectiveness.
“Walkthrough”Follow one transaction through the system to understand process and confirm design/implementation.
“Test of control”Inspect evidence that control operated, who performed it, when, and whether exceptions were resolved.
“Control deficiency”Explain weakness, audit risk, recommendation, and effect on substantive work.
“Management letter”Communicate control deficiencies and recommendations; do not confuse with audit opinion modification unless FS are materially misstated or scope-limited.

Control Categories

Control TypePurposeExamples
PreventiveStop errors/fraud before they occurCredit approval, purchase order authorization, segregation of duties
DetectiveIdentify errors/fraud after occurrenceBank reconciliations, exception reports, inventory variance review
IT general controlsSupport reliable systemsAccess controls, change management, backups, operations controls
Application controlsProcess-level automated controlsThree-way match, edit checks, automated pricing
Monitoring controlsOngoing oversightManagement review, internal audit, board/committee review

Segregation of Duties

Separate these functions where possible:

FunctionShould Be Separated From
AuthorizationCustody and recording
Custody of assetsRecording and reconciliation
Recording transactionsReconciliation and review
System administrationTransaction processing
Vendor/customer master file changesPayment/receipt processing

How to Write a Control Weakness Response

Use a 4-part structure:

  1. Weakness: What is wrong?
  2. Implication: What could go wrong?
  3. Recommendation: What should management implement?
  4. Audit impact: How does this affect risk/procedures?

Example:

ElementExample
WeaknessThe accounts payable clerk can create vendors and process payments.
ImplicationFictitious vendors or unauthorized payments could be processed and concealed.
RecommendationVendor creation should require independent approval, and payment runs should be reviewed by someone outside AP.
Audit ImpactIncrease fraud risk in purchases/cash disbursements; test vendor master changes and subsequent payments.

Fraud, Laws, and Professional Skepticism

AreaWhat to remember
Fraud trianglePressure, opportunity, rationalization. Use case facts to identify risk.
Revenue recognitionPresumed high-risk area unless rebutted with strong rationale.
Management overrideTest journal entries, accounting estimates for bias, and significant unusual transactions.
Non-complianceConsider effect on FS, disclosure, audit evidence, and communication with governance.
SkepticismCorroborate management explanations; challenge inconsistent evidence.
CommunicationEscalate significant fraud risks, suspected fraud, and material control deficiencies to appropriate governance level.

Sampling and Misstatement Evaluation

Sampling Factors

Desired outcomeSample size effect
Higher assuranceIncrease sample size.
Lower tolerable misstatement/deviationIncrease sample size.
Higher expected misstatement/deviationIncrease sample size.
Stronger controls / lower assessed riskMay reduce sample size if reliance is justified.
More variable populationIncrease sample size.
Larger populationUsually limited effect after population is large; risk and variability matter more.
Notes and examples

Misstatement Types

TypeMeaningExample
FactualNo judgement involvedInvoice recorded twice.
JudgementalDifference in estimate or accounting policy judgementAllowance too low.
ProjectedAuditor projects sample error to populationSample error rate applied to full population.

Evaluation Steps

  1. Accumulate identified misstatements, including projected and judgemental differences.
  2. Ask management to correct them.
  3. Reassess materiality if circumstances changed.
  4. Consider qualitative factors, not only dollar amount.
  5. Evaluate whether uncorrected misstatements are material individually or in aggregate.
  6. Conclude on report modification if material misstatement remains.

Reporting Decision Reference

    graph TD
	    A[Issue identified] --> B{Misstatement or scope limitation?}
	    B -->|Misstatement| C{Material?}
	    C -->|No| D[Unmodified opinion; communicate if needed]
	    C -->|Yes| E{Pervasive?}
	    E -->|No| F[Qualified opinion: except for]
	    E -->|Yes| G[Adverse opinion]
	    B -->|Scope limitation| H{Material possible effects?}
	    H -->|No| D
	    H -->|Yes| I{Pervasive?}
	    I -->|No| J[Qualified opinion: except for possible effects]
	    I -->|Yes| K[Disclaimer of opinion]
	    B -->|Emphasis or context| L{FS appropriately presented?}
	    L -->|Yes| M[Unmodified plus EOM/Other Matter if appropriate]
	    L -->|No| C
Notes and examples

Opinion Modification Table

ConditionMaterial but not pervasiveMaterial and pervasive
Material misstatementQualified opinionAdverse opinion
Inability to obtain sufficient appropriate evidenceQualified opinionDisclaimer of opinion

Emphasis and Other Matter

ParagraphUse whenKey distinction
Emphasis of MatterMatter is appropriately presented/disclosed in FS and is fundamental to users’ understandingDoes not modify opinion.
Other MatterMatter outside FS is relevant to users’ understanding of audit, responsibilities, or reportDoes not modify opinion.
Material Uncertainty Related to Going ConcernAdequate disclosure of material uncertainty existsSeparate communication; not an adverse opinion if disclosure is adequate.

Going Concern Reporting

SituationReporting implication
No material uncertainty and going-concern basis appropriateUnmodified, no special going-concern section required solely for routine risk.
Material uncertainty exists and disclosure is adequateUnmodified opinion with Material Uncertainty Related to Going Concern section when required.
Material uncertainty exists and disclosure inadequateModified opinion due to material misstatement.
Going-concern basis inappropriateAdverse opinion if FS prepared on going-concern basis.
Insufficient evidence due to management limitationsQualified opinion or disclaimer depending on materiality/pervasiveness.

Audit Opinion Decision Table

SituationReporting Result
Sufficient appropriate evidence; no material misstatementUnmodified opinion
Material misstatement, not pervasiveQualified opinion
Material misstatement, pervasiveAdverse opinion
Scope limitation, material but not pervasiveQualified opinion
Scope limitation, material and pervasiveDisclaimer of opinion
Important matter properly presented/disclosedConsider emphasis of matter
Matter relevant to users’ understanding of audit/reportConsider other matter

Material vs Pervasive

ConceptMeaning
MaterialCould influence user decisions
PervasiveNot confined to specific elements, represents substantial portion of statements, or fundamental to users’ understanding

Quick decision rule:

  • Material but isolated → usually qualified.
  • Material and widespread/fundamental → adverse or disclaimer, depending on whether the issue is misstatement or lack of evidence.
  • Properly disclosed but important → consider emphasis, not modification.

Emphasis of Matter vs Other Matter

ParagraphUsed ForKey Condition
Emphasis of matterMatter presented/disclosed in the financial statementsAuditor wants to draw attention; opinion not modified
Other matterMatter not presented/disclosed in the financial statementsRelevant to users’ understanding of audit, responsibilities, or report

Common trap: Do not use emphasis of matter to “fix” inadequate disclosure. If disclosure is materially inadequate, consider modification.

Review, Compilation, and AUP Traps

TopicCorrect treatment
Review proceduresPrimarily inquiry and analytical procedures; perform additional procedures when information appears inconsistent, incomplete, or implausible.
Review materialityStill applies; limited assurance does not mean no materiality.
Review evidenceLess persuasive than audit evidence, but must support limited assurance conclusion.
CompilationPractitioner compiles information; no verification and no assurance conclusion.
Compilation basis of accountingMust be understandable to users; watch for misleading information.
AUP engagementProcedures are agreed with engaging party; report factual findings only.
Users drawing conclusionsAUP users evaluate findings themselves; practitioner does not conclude.

Special Assurance Engagements

Subject Matter and Criteria

ElementCase questions to answer
Subject matterWhat is being measured or evaluated? Financial data, compliance, controls, GHG emissions, performance metrics?
CriteriaAre criteria relevant, complete, reliable, neutral, and understandable? Are they available to users?
Responsible partyWho is responsible for subject matter or subject matter information?
UsersWho will rely on the report and for what decision?
Assurance levelReasonable or limited? Is the requested level feasible?
EvidenceCan sufficient appropriate evidence be obtained?
Report restrictionAre criteria or users specialized enough to restrict distribution or use?
Notes and examples

Direct vs Attestation

FeatureDirect engagementAttestation engagement
Who measures/evaluates subject matter?PractitionerResponsible party or evaluator
Practitioner reports onOutcome of practitioner’s evaluationSubject matter information prepared by another party
Canadian standard familyCSAE 3001CSAE 3000
ExamplePractitioner evaluates whether controls meet criteriaManagement asserts controls meet criteria; practitioner reports on assertion

Review Engagement Cheat Sheet

A review provides limited assurance, so the work is narrower than an audit.

Review Engagement Procedures

Typical review procedures:

  • Inquiries of management and relevant personnel.
  • Analytical procedures.
  • Discussion of unexpected fluctuations.
  • Reading financial statements for plausibility.
  • Follow-up procedures when information appears inconsistent or misstated.

A review answer should not default to audit-level testing unless the case facts require follow-up on suspicious or inconsistent information.

IssueReview-Level Response
Revenue increased sharplyAsk management for explanation; compare to sales records/trends; perform analytics by month/customer/product; follow up unusual items
Receivables aging worsenedDiscuss collectability; compare subsequent collections; assess allowance reasonableness
Inventory margins changedAnalyze gross margin; discuss obsolete inventory; compare to post-year-end sales if needed
New debtInquire about terms; inspect agreement if necessary; assess classification/disclosure
Inconsistent explanationPerform additional procedures to resolve inconsistency

High-Yield CAS Area Map

AreaWhat candidates should be ready to apply
CAS 200 / 230Overall objectives, professional skepticism, documentation sufficient for experienced auditor.
CAS 210Engagement terms and preconditions.
CAS 240Fraud, revenue recognition, management override.
CAS 250Laws and regulations affecting FS.
CAS 260 / 265Communication with governance and control deficiencies.
CAS 300 / 315 / 330Planning, risk assessment, responses to assessed risks.
CAS 320 / 450Materiality and evaluation of misstatements.
CAS 500 / 505 / 520 / 530Evidence, confirmations, analytics, sampling.
CAS 540Accounting estimates and bias.
CAS 550Related parties.
CAS 560Subsequent events.
CAS 570Going concern.
CAS 580Written representations.
CAS 600 / 610 / 620Group audits, internal audit work, auditor’s expert.
CAS 700 / 705 / 706Opinion formation, modifications, emphasis/other matter.
CAS 720Other information and inconsistencies.

Subsequent Events Cheat Sheet

TimingAuditor responsibilityTypical procedures
Between year-end and auditor’s report datePerform procedures to identify events requiring adjustment or disclosureRead minutes, inquire, review interim FS, inspect subsequent transactions, obtain legal updates.
After report date but before FS issuedNo active search obligation, but respond to facts that become knownDiscuss with management, determine amendment need, perform necessary procedures, update report if appropriate.
After FS issuedRespond if facts existed at report date and would have affected reportDiscuss with management/governance, consider revised FS/report, legal/professional advice if management refuses.

Adjusting vs Non-Adjusting

EventTreatment
Provides evidence of conditions existing at year-endAdjust FS.
Indicates conditions arose after year-endDisclose if material; do not adjust amounts.
Affects going concernMay require adjustment to basis of accounting or expanded disclosure.

Case-Writing Templates

Audit Planning Memo Skeleton

SectionWhat to include
Users and objectivesWho relies on the report and what decisions they make.
Engagement acceptanceIndependence, competence, management integrity, preconditions, scope.
MaterialityBenchmark, calculation if possible, qualitative factors, performance materiality.
Risk assessmentInherent/control risks, fraud risks, significant risks, affected assertions.
Audit approachControls reliance vs substantive approach; timing; staffing; specialists.
ProceduresSpecific, assertion-linked procedures for high-risk areas.
ReportingPotential modifications, EOM/Other Matter, going concern, restrictions.
Notes and examples

Assurance Procedure Formula

Use this structure in case answers:

  1. To address the risk/assertion.
  2. Select the population and sample basis.
  3. Perform a clear audit action.
  4. Agree/compare/recalculate/confirm to a named source or criterion.
  5. Investigate exceptions and quantify misstatements.

Example: “To test revenue cutoff, select sales recorded in the last five business days before year-end and first five business days after year-end, agree each invoice to shipping documentation and contract terms, verify the date goods were transferred, and investigate items recorded in the wrong period.”

Control Recommendation Formula

ComponentExample
WeaknessSales staff can create customers and approve credit limits.
ImplicationFictitious customers or sales to poor-credit customers may result in bad debts or fraudulent revenue.
RecommendationLimit customer setup to accounting and require credit manager approval for credit limits.
BenefitReduces unauthorized customers and improves collectability of receivables.

Reporting Analysis Formula

  1. Identify the unresolved issue.
  2. Quantify misstatement or possible misstatement.
  3. Compare to materiality and qualitative factors.
  4. Decide if pervasive.
  5. State report effect and wording direction.

Practical Case Response Method

For each issue:

  1. Identify the issue clearly.

    • “Revenue cutoff risk exists because sales increased significantly in the final week of the year.”
  2. Explain why it matters.

    • Link to users, materiality, assertion, risk, or reporting.
  3. Apply case facts.

    • Use the numbers, dates, incentives, controls, agreements, and constraints provided.
  4. Recommend procedures or actions.

    • Be specific and feasible.
  5. Conclude.

    • State impact on engagement, report, control recommendation, or next step.

Time Management Traps

Avoid spending too much time on:

  • Generic definitions.
  • Long standard summaries without application.
  • Perfect materiality calculations at the expense of procedures.
  • Rewriting case facts.
  • Listing every possible procedure instead of the best procedures.
  • Over-auditing a review or compilation engagement.

What Markers Usually Reward in Assurance Responses

Strong responses tend to be:

  • Case-specific.
  • Risk-based.
  • Linked to assertions.
  • Clear about assurance level.
  • Practical and professionally worded.
  • Conclusive when reporting or acceptance decisions are required.

Weak responses tend to be:

  • Generic.
  • Procedure lists with no risk link.
  • Missing the report impact.
  • Confusing audit, review, and compilation.
  • Ignoring independence.
  • Failing to explain materiality or pervasiveness.

Common CPA Assurance Exam Traps

TrapBetter approach
Listing standards without applying factsTie each point to users, risks, materiality, assertions, and case constraints.
Vague proceduresWrite procedures specific enough that an audit junior could perform them.
Ignoring accounting impactAssurance conclusions often depend on whether the accounting treatment is materially misstated.
Confusing review with auditReviews use inquiry/analytics and limited assurance; audits require sufficient appropriate evidence for reasonable assurance.
Calling compilation assuranceCompilation provides no assurance.
Forgetting qualitative materialityFraud, covenants, compliance, trends, and related parties can make small amounts material.
Modifying opinion too quicklyFirst determine misstatement vs scope limitation, materiality, pervasiveness, and disclosure adequacy.
Treating control deficiencies as automatic report modificationsControl deficiencies affect audit approach and may be communicated; opinion changes only if FS issue or scope issue remains.
Omitting conclusionEvery issue needs a recommendation or conclusion, even if brief.

Final Practice Step

Next, practise with timed CPA Assurance cases: for each issue, force yourself to write the standard/engagement choice, risk, materiality impact, specific procedures, and reporting conclusion in a concise case format.

CPA Canada PEP Assurance Elective Quick Orientation

This Cheat Sheet is for candidates preparing for the CPA Canada PEP Assurance Elective using the official exam code CPA Assurance. It is independent review support, not affiliated with CPA Canada, and is designed to help you refresh high-yield concepts before using topic drills, mock exams, original practice questions, and detailed explanations.

The Assurance elective rewards candidates who can:

  • Identify the correct engagement type and reporting implications.
  • Link risk, materiality, assertions, controls, and procedures.
  • Write practical, case-specific audit or review procedures.
  • Recognize independence, ethical, governance, and acceptance issues.
  • Explain reporting options clearly when evidence, scope, or misstatement issues exist.
  • Manage case time by prioritizing the most significant assurance matters.

High-Yield Assurance Framework

The Core Assurance Logic

Most assurance case issues can be handled with this sequence:

  1. What is the user asking for?

    • Audit opinion?
    • Review conclusion?
    • No-assurance compilation?
    • Specific agreed procedures?
    • Internal control or special-purpose reporting?
  2. What level of assurance is appropriate?

    • Reasonable assurance: positive opinion.
    • Limited assurance: negative-form conclusion.
    • No assurance: compilation or advisory support.
  3. What are the risks?

    • Financial statement risk.
    • Engagement risk.
    • Independence risk.
    • Reporting risk.
    • User expectation risk.
  4. What evidence is needed?

    • Inspection, observation, inquiry, confirmation, recalculation, reperformance, analytical procedures.
  5. What is the reporting consequence?

    • Clean/unmodified report?
    • Modified opinion/conclusion?
    • Emphasis or other matter?
    • Withdrawal or decline engagement?
    flowchart TD
	A[Client request or case issue] --> B{Is assurance required?}
	B -->|Yes| C{Reasonable or limited assurance?}
	B -->|No| D[Compilation/advisory/no assurance]
	C -->|Reasonable| E[Audit: assess risks, controls, substantive evidence]
	C -->|Limited| F[Review: inquiry + analytics + targeted follow-up]
	E --> G{Sufficient appropriate evidence?}
	F --> G
	G -->|Yes| H{Material misstatement?}
	G -->|No| I[Scope limitation: consider qualified/disclaimer]
	H -->|No| J[Unmodified opinion/conclusion]
	H -->|Yes| K{Material and pervasive?}
	K -->|Material not pervasive| L[Qualified opinion/conclusion]
	K -->|Material and pervasive| M[Adverse opinion/conclusion]

Engagement Type Decision Table

Engagement / ServiceAssurance LevelTypical Work EffortReport Wording LogicCommon Exam Trap
Audit of financial statementsReasonable assuranceRisk assessment, controls understanding, substantive procedures, sufficient appropriate evidencePositive opinion on whether financial statements are fairly presented / prepared in accordance with applicable frameworkWriting only review-level procedures for an audit
Review engagementLimited assurancePrimarily inquiry, analytical procedures, discussion, follow-up on unusual itemsNegative-form conclusion: nothing has come to attention causing belief statements are misstatedTreating a review like a full audit
Compilation engagementNo assuranceCompile information based on management-provided data; consider whether information appears misleadingNo assurance expressedSaying the practitioner “verifies” or “provides assurance”
Agreed-upon proceduresNo assurance opinion; factual findingsPerform only procedures agreed with specified partiesReport factual findings, not conclusionRecommending broad assurance language
Special-purpose financial statementsVaries by engagementProcedures depend on framework and user needsMay require specific reporting references to special-purpose frameworkIgnoring basis of accounting and restricted users
Internal control reportingVariesAssess design and/or operating effectiveness depending on scopeConclusion depends on criteria and engagement termsConfusing design effectiveness with operating effectiveness

Audit Risk, Materiality, and Assertions

Audit Risk Model

Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated.

\[ \text{Audit Risk} = \text{Inherent Risk} \times \text{Control Risk} \times \text{Detection Risk} \]

Practical exam use:

  • If inherent risk is high, plan more persuasive evidence.
  • If control risk is high, reduce reliance on controls and increase substantive testing.
  • If acceptable detection risk must be low, perform more effective substantive procedures, closer to year-end, with larger sample sizes or more reliable evidence.
Notes and examples

Inherent Risk Indicators

IndicatorWhy It MattersLikely Audit Response
Complex estimatesMore judgment and bias riskTest assumptions, methods, data, sensitivity
Rapid growthRevenue cutoff, collectability, inventory, controls may lagExpand revenue, receivables, inventory testing
New accounting systemData migration and control failure riskTest conversion, access controls, reconciliations
Financing pressureIncentive to overstate assets/profits or understate liabilitiesIncrease fraud-focused procedures
Related-party transactionsNon-arm’s-length terms and disclosure riskInspect agreements, board minutes, confirmations
Management bonus targetsBias in estimates and revenue recognitionApply professional skepticism to judgment areas
Going concern pressureDisclosure and valuation issuesCash flow review, financing support, covenant analysis

Materiality: What to Say in a Case

Materiality affects planning, procedure extent, evaluating misstatements, and reporting. In a case response, do more than calculate a number.

Include:

  • Benchmark selected and why it is appropriate.
  • Percentage applied and why risk supports higher/lower end.
  • Performance materiality if relevant for planning testing.
  • Qualitative materiality items even if quantitatively small.
  • Reporting impact if misstatements are material.

Common qualitative materiality factors:

  • Turns profit into loss or affects trends.
  • Affects debt covenants, bonuses, financing, or regulatory compliance.
  • Involves fraud, illegal acts, related parties, or management integrity.
  • Changes key ratios or user decisions.
  • Affects disclosures important to users.

Audit Evidence: Reliability Rules

Evidence Persuasiveness

Sufficient appropriate evidence depends on both quantity and quality.

Evidence TypeReliability NotesExam Use
External confirmationOften highly reliable if controlled by auditorStrong for receivables, cash, debt, legal claims
Auditor reperformanceHighly persuasive for calculations/controlsUse for depreciation, interest, reconciliations, control operation
Inspection of original documentsStronger than copies or verbal statementsGood for contracts, invoices, title documents
ObservationUseful but limited to point in timeInventory count, control performance
InquiryNecessary but weak alonePair with corroborating evidence
Analytical proceduresUseful for risk assessment and reviewsStronger when expectations are precise and data reliable
Management representationLowest standalone reliabilitySupportive only; not substitute for other evidence
Notes and examples

Common Evidence Mistakes

Avoid writing:

  • “Discuss with management” as the only procedure for a material issue.
  • “Ensure revenue is correct” without saying how.
  • “Check invoices” without specifying direction of test.
  • “Review documents” without identifying documents and assertion.
  • “Compare to prior year” as sufficient evidence for a high-risk audit area.
  • “Obtain management representation” as the primary procedure.

Better procedure wording:

Select a sample of sales recorded in the final two weeks of the year and the first two weeks after year-end. Trace each sale to the sales invoice, shipping document, customer contract, and subsequent cash receipt to determine whether revenue was recorded in the correct period and only when performance obligations were satisfied.

Substantive Procedures by Major Cycle

Revenue and Receivables

High-risk areas:

  • Premature revenue recognition.
  • Side agreements or return rights.
  • Cutoff errors.
  • Collectability issues.
  • Related-party sales.
  • Bill-and-hold or consignment arrangements.
Notes and examples

Useful procedures:

  • Test sales before and after year-end for cutoff.
  • Trace recorded sales to contracts, shipping, invoices, and cash receipts.
  • Confirm receivables with customers.
  • Review subsequent collections.
  • Analyze credit notes after year-end.
  • Review aged receivables and allowance assumptions.
  • Investigate unusual margins, manual journal entries, and sales spikes.

Inventory and Cost of Sales

  • Existence at year-end.

  • Obsolescence or net realizable value.

  • Count errors.

  • Consigned goods.

  • Standard costing and overhead allocation.

  • Cutoff of purchases and sales.

  • Attend inventory count and perform test counts floor-to-sheet and sheet-to-floor.

  • Inspect damaged or slow-moving inventory.

  • Test pricing to invoices or cost records.

  • Compare cost to selling price less costs to sell.

  • Review post-year-end sales of inventory.

  • Test cutoff using receiving and shipping documents.

  • Reconcile count sheets to final inventory listing.

Purchases, Payables, and Accruals

  • Unrecorded liabilities.

  • Expense cutoff.

  • Unauthorized purchases.

  • Related-party suppliers.

  • Capitalization of expenses.

  • Search subsequent disbursements for liabilities existing at year-end.

  • Review unmatched receiving reports and supplier statements.

  • Inspect invoices received after year-end.

  • Test cutoff around year-end receiving dates.

  • Review board minutes and contracts for obligations.

  • Analyze expense trends and investigate unusual decreases.

Cash and Debt

  • Restrictions on cash.

  • Unrecorded debt.

  • Covenant breaches.

  • Incorrect classification.

  • Interest accrual errors.

  • Confirm bank balances and debt directly.

  • Review bank reconciliations and outstanding items.

  • Inspect loan agreements.

  • Recalculate interest.

  • Test covenant calculations.

  • Review classification of current vs long-term debt.

  • Inspect correspondence with lenders.

Payroll

  • Ghost employees.

  • Unauthorized rate changes.

  • Incorrect vacation/bonus accruals.

  • Terminated employees still paid.

  • Reconcile payroll register to general ledger.

  • Test new hires and terminations to HR approvals.

  • Review master file changes.

  • Recalculate gross-to-net pay.

  • Compare payroll expense trends to headcount.

  • Test bonus/vacation accrual assumptions.

Special Topics Candidates Often Miss

Fraud Risk

Fraud risk is not solved by asking management whether fraud occurred. Address incentives, opportunities, and rationalization.

Common fraud-focused procedures:

  • Test manual journal entries, especially late, unusual, round-dollar, or posted by senior staff.
  • Review accounting estimates for management bias.
  • Investigate significant unusual transactions.
  • Perform unpredictable procedures.
  • Evaluate revenue recognition risk.
  • Consider management override of controls.
Notes and examples

Related-party risks include incomplete disclosure, non-arm’s-length pricing, hidden obligations, and earnings manipulation.

Procedures:

  • Review board minutes and shareholder records.
  • Ask management and governance bodies about relationships.
  • Inspect unusual transactions and contracts.
  • Confirm terms directly where appropriate.
  • Compare terms to market terms if possible.
  • Ensure disclosures are complete and understandable.

Accounting Estimates

For estimates, focus on method, data, assumptions, and bias.

Estimate AreaAudit Focus
Allowance for doubtful accountsAging, subsequent collections, customer credit risk
Warranty provisionHistorical claims, current sales, product changes
Inventory obsolescenceSlow-moving items, post-year-end sales, write-down history
Fair valueValuation model, assumptions, external data, expert competence
ImpairmentCash flow forecasts, discount rates, sensitivity analysis
Legal provisionLegal letters, probability assessment, range of outcomes

Going Concern

Going concern issues often combine audit, financial reporting, and disclosure.

Indicators:

  • Recurring losses or negative cash flows.

  • Loan covenant breaches.

  • Expiring financing with no renewal.

  • Loss of major customer or supplier.

  • Inability to pay debts when due.

  • Significant legal claims.

  • Review cash flow forecasts and assumptions.

  • Compare forecasts to historical accuracy.

  • Inspect financing agreements and renewals.

  • Confirm support from lenders or owners where relevant.

  • Review covenant compliance.

  • Inspect subsequent cash receipts/disbursements.

  • Assess disclosure adequacy.

Compilation and No-Assurance Services

Compilation engagements are commonly tested because candidates may accidentally imply assurance.

Key points:

  • No assurance is expressed.
  • Management is responsible for information.
  • Practitioner compiles based on information provided.
  • Practitioner should consider whether information appears misleading.
  • Independence may need to be addressed depending on circumstances and reporting.

Common wording trap:

  • Weak: “We will audit the numbers for accuracy.”
  • Better: “A compilation does not provide assurance; users should understand that procedures are not designed to verify completeness or accuracy.”

Acceptance, Continuance, and Independence

Client Acceptance / Continuance Checklist

Before accepting or continuing, consider:

AreaQuestions to Ask
Management integrityAny history of fraud, aggressive reporting, unpaid fees, or pressure?
CompetenceDoes the firm have expertise, time, and resources?
IndependenceAny financial, employment, family, business, or advocacy threats?
PreconditionsIs the framework acceptable? Does management accept responsibility?
ScopeAre there restrictions that prevent sufficient evidence?
UsersWho will rely on the report? Are expectations clear?
FeesAre fees contingent or overdue in a way that creates threats?
Engagement termsIs there a clear engagement letter?
Notes and examples

Independence Threats and Safeguards

ThreatExamplePossible Safeguards
Self-interestFinancial interest in client; significant overdue feesRemove interest, collect fees, independent review
Self-reviewAuditor prepared records being auditedSeparate teams, independent review, decline service
AdvocacyPromoting client financingLimit role, avoid advocacy, independent review
FamiliarityLong association or close relationshipRotate staff, independent quality review
IntimidationManagement threatens replacement or fee pressureEscalate, governance communication, consider withdrawal

Common exam mistake: identifying an independence threat without concluding whether it is significant and what safeguard or action is required.

Governance and Communication

Assurance cases may require recommendations to management, the board, audit committee, or owners.

Communicate:

  • Significant risks.
  • Fraud or suspected fraud.
  • Significant deficiencies in internal control.
  • Uncorrected misstatements.
  • Independence matters.
  • Scope limitations.
  • Significant accounting policy or estimate issues.
  • Going concern concerns.
  • Disagreements with management.

When governance is weak, recommend practical improvements:

  • Independent board or audit committee oversight.
  • Regular financial reporting package.
  • Approval limits.
  • Conflict-of-interest policy.
  • Whistleblower process.
  • Internal audit or periodic control review.
  • Formal budgeting and variance analysis.

Writing Strong Assurance Procedures

Procedure Formula

Use this structure:

Select / obtain / inspect / recalculate / confirm / observe + specific item + source document + purpose/assertion.

Examples:

Weak ProcedureStronger Procedure
Check revenue.Select revenue transactions recorded near year-end and trace to shipping documents and customer contracts to test cutoff and occurrence.
Review allowance.Compare the aged receivables listing to subsequent cash receipts and customer credit history to assess valuation of the allowance.
Test inventory.Perform floor-to-sheet and sheet-to-floor test counts during the inventory count to test existence and completeness.
Look at expenses.Search subsequent disbursements and unmatched receiving reports for liabilities existing at year-end to test completeness of payables.
Ask about debt.Confirm debt balances and terms with lenders and inspect loan agreements to test completeness, classification, and covenant disclosure.
Notes and examples

Directional Testing

Direction matters.

ConcernStart FromTrace ToAssertion
Recorded sale may not existGeneral ledger / sales listingInvoice, shipping, contract, cash receiptOccurrence
Sale may be omittedShipping documents / ordersSales journal / GLCompleteness
Payable may be omittedSubsequent payments / receiving reportsPayables listing / GLCompleteness
Inventory may not existInventory listingPhysical inventoryExistence
Inventory may be incompletePhysical inventoryInventory listingCompleteness

Rapid Review Tables

Engagement Planning Checklist

Planning AreaAsk Yourself
UsersWho relies on the report and why?
FrameworkWhat reporting framework applies?
Engagement typeAudit, review, compilation, agreed procedures, special report?
IndependenceAre there threats and safeguards?
MaterialityWhat benchmark and qualitative factors apply?
RisksWhat could be materially misstated?
ControlsCan controls be relied on or are they weak?
EvidenceWhat procedures provide sufficient appropriate evidence?
SpecialistsAre valuation, tax, actuarial, IT, or legal experts needed?
ReportingWhat opinion/conclusion/modification may be required?
Notes and examples

Common Assurance Issue → Likely Response

Case FactLikely IssueCandidate Response
Client wants financingHigher user reliance; possible biasLower materiality, heightened skepticism, test debt/covenants/forecast assumptions
Owner pressures accountant to “make numbers work”Integrity and fraud riskConsider acceptance, governance communication, expanded fraud procedures
New ERP systemIT/control and data migration riskTest access, change management, conversion reconciliations
Inventory count not attendedScope limitation or alternative proceduresPerform alternative existence procedures; assess report impact if insufficient
Major lawsuitContingency completeness/valuation/disclosureLegal letter, minutes, correspondence, subsequent events
Significant sales after year-end creditsRevenue occurrence/returns riskTest credit notes, returns policy, cutoff, collectability
Missing bank confirmationsEvidence limitationFollow up confirmations; alternative procedures; reporting impact
Management refuses adjustmentMisstatementEvaluate materiality/pervasiveness; modify if necessary

Common Candidate Mistakes to Fix Before Practice

  • Recommending an audit when the user only needs limited assurance or no assurance.
  • Forgetting that compilation provides no assurance.
  • Writing procedures that are too vague to perform.
  • Not linking procedures to assertions.
  • Ignoring independence threats because the issue “feels small.”
  • Treating all misstatements as qualified opinions without assessing pervasiveness.
  • Using emphasis of matter for an uncorrected misstatement.
  • Concluding on going concern without discussing disclosures.
  • Relying only on management inquiry for high-risk areas.
  • Missing qualitative materiality.
  • Failing to use case facts in the recommendation.
  • Spending too long calculating and too little explaining.

Quick Practice Plan

Use this review page first, then move immediately into independent companion practice:

  1. Do short topic drills on materiality, assertions, reporting, and engagement type.
  2. Write procedures from scratch, then compare to detailed explanations.
  3. Complete mixed original practice questions that force you to identify the engagement type before choosing procedures.
  4. Attempt timed mini-cases focused on risk, controls, and reporting.
  5. Review every missed question by asking:\
    • Did I identify the right assurance level?\
    • Did I link risk to assertion?\
    • Did I write a procedure that would actually produce evidence?\
    • Did I conclude on reporting or engagement impact?

Final Exam-Prep Reminder

For the CPA Canada PEP Assurance Elective under exam code CPA Assurance, the fastest improvement usually comes from practicing applied case responses, not memorizing isolated definitions. Use this Cheat Sheet to refresh the decision rules, then move into a question bank with original practice questions, topic drills, mock cases, and detailed explanations so you can apply the concepts under exam-style time pressure.

Put the review into practice