CPA AUD Cheat Sheet: Auditing and Attestation Cheat Sheet
Last revised: September 28, 2026
Cheat sheet: CPA AUD reference for audit risk, evidence, reporting, ethics, attestations, reviews, compilations, and high-yield AICPA exam distinctions.
Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.
Scope and study context
For AUD questions, think in this order:
What engagement is being performed? Audit, review, compilation, preparation, examination, agreed-upon procedures, issuer audit, nonissuer audit, government audit.
What standard applies? AICPA GAAS, PCAOB, SSARS, SSAE, GAGAS, or special reporting guidance.
What assertion or objective is at risk? Existence, completeness, valuation, rights/obligations, cutoff, classification, presentation.
What evidence is most persuasive? External, direct, written, original, generated under strong controls.
What report wording or modification follows? Unmodified, qualified, adverse, disclaimer, emphasis-of-matter, other-matter, restricted-use, no assurance.
For CPA AUD, quick review only helps if you immediately apply it. After reading a section:
Do focused topic drills on that area.
Review detailed explanations for both correct and incorrect answers.
Track whether mistakes are due to standards knowledge, assertion matching, report selection, or wording traps.
Rework missed questions after a delay.
Move to mixed sets only after individual weak areas improve.
A practical next step is to use an independent companion practice question bank with original practice questions, topic drills, mock exams, and detailed explanations focused on AICPA U.S. CPA AUD - Auditing and Attestation (CPA AUD).
Standards and Engagement Selection
Engagement / subject matter
Common standards
Assurance level
Practitioner output
High-yield exam point
Audit of nonissuer historical financial statements
AICPA GAAS / AU-C
Reasonable assurance
Opinion on whether F/S are fairly presented
Auditor obtains sufficient appropriate evidence; not absolute assurance
Audit of issuer financial statements
PCAOB auditing standards
Reasonable assurance
Opinion under PCAOB reporting model
Issuer audits have PCAOB reporting and independence requirements
Integrated audit of issuer F/S and ICFR
PCAOB
Reasonable assurance on both
Opinions on F/S and internal control over financial reporting
Material weakness in ICFR requires adverse ICFR opinion
Review of nonissuer historical F/S
SSARS
Limited assurance
Conclusion: not aware of material modifications
Primarily inquiry and analytical procedures; no opinion
Compilation of nonissuer F/S
SSARS
No assurance
Compilation report
Independence not required, but lack of independence must be disclosed
Preparation of F/S
SSARS
No assurance
Prepared statements, generally no report
Each page should indicate no assurance or disclaimer is required
Examination of subject matter or assertion
SSAE / AT-C
Reasonable assurance
Opinion
Similar assurance level to an audit, but on non-F/S subject matter
Attestation review
SSAE / AT-C
Limited assurance
Conclusion
Less evidence than examination; more than compilation
Agreed-upon procedures
SSAE / AT-C
No assurance
Procedures and findings
Practitioner does not conclude; users draw conclusions
Change nature, timing, and extent of audit procedures
Audit risk
Auditor gives inappropriate opinion
Indirectly
Lower detection risk when RMM is high
High-Yield Risk Relationship
If assessed RMM is…
Detection risk should be…
Evidence should be…
Higher
Lower
More persuasive, often more year-end testing
Lower
Higher
Less extensive, but still sufficient and appropriate
Common trap: Higher inherent/control risk does not mean higher detection risk. It means the auditor must accept lower detection risk and perform stronger procedures.
Materiality Cheat Sheet
Term
Practical meaning
Common trap
Overall materiality
Amount that could influence users’ decisions on F/S as a whole
Not the same as tolerable misstatement
Performance materiality
Lower amount used to reduce risk that aggregate misstatements exceed overall materiality
Used to plan nature, timing, extent
Tolerable misstatement
Maximum misstatement accepted in a population during sampling
Applied to specific account/class testing
Clearly trivial threshold
Amount below which misstatements need not be accumulated
Attorney refusal or limitation may create scope limitation
Notes and examples
Revenue and Receivables
Risk/assertion
Strong procedures
AR existence
Positive confirmations, subsequent cash receipts
Sales occurrence
Vouch recorded sales to shipping docs/orders
Sales completeness
Trace shipping documents to sales invoices/journal
Cutoff
Test shipments around year-end
Allowance valuation
Aging analysis, subsequent collections, historical loss rates
Fraud risk
Journal entries, side agreements, unusual terms
Common trap: Negative confirmations are appropriate only when risk is low, controls are effective, balances are small/homogeneous, and recipients are expected to respond if incorrect.
Inventory
Risk/assertion
Strong procedures
Existence/condition
Observe physical count
Completeness
Trace floor counts to final inventory records
Rights
Inspect consignment/warehouse agreements
Valuation
Test cost, lower of cost and net realizable value, obsolescence
Cutoff
Test receiving/shipping around year-end
If inventory observation is impracticable, the auditor performs alternative procedures. If sufficient evidence cannot be obtained, consider a scope limitation.
Purchases, Payables, and Expenses
Risk/assertion
Strong procedures
AP completeness
Search for unrecorded liabilities
Expense cutoff
Review receiving reports and vendor invoices around year-end
Validity
Vouch recorded purchases to purchase orders/receiving reports
Accrued liabilities
Review subsequent disbursements
Related parties
Inspect board minutes, contracts, confirmations
Search for unrecorded liabilities usually focuses on understatement, so it starts with subsequent cash disbursements, unmatched receiving reports, vendor statements, and invoices.
Cash
Risk/assertion
Strong procedures
Existence
Bank confirmations
Completeness
Bank reconciliations, cutoff bank statements
Kiting
Interbank transfer schedule
Restrictions
Review agreements and disclosures
Fraud
Surprise counts, segregation of duties review
Payroll
Risk/assertion
Strong procedures
Occurrence
Compare payroll to HR records/time approvals
Completeness
Reconcile payroll tax filings to payroll records
Authorization
Inspect approval of pay rates
Segregation
Separate HR authorization, timekeeping, payroll processing, distribution
Debt and Equity
Risk/assertion
Strong procedures
Completeness
Confirm debt with lenders, inspect board minutes
Classification
Review maturity dates and covenant terms
Valuation
Recalculate interest and amortization
Disclosure
Review covenants, collateral, restrictions
Equity authorization
Inspect minutes and shareholder records
Estimates and Fair Value
Risk/assertion
Strong procedures
Reasonableness
Evaluate method, assumptions, and data
Bias
Retrospective review of prior estimates
Specialist use
Evaluate competence, capability, objectivity
Fair value
Compare to market data or independent pricing
Disclosure
Review sensitivity and uncertainty disclosures
Common trap: The auditor does not simply accept management’s estimate because it is complex. Complexity often increases inherent risk.
Confirmations
Confirmation type
Use when
Evidence strength
Common trap
Positive confirmation
Large balances, high risk, expected disputes, complex accounts
Higher
Nonresponse requires follow-up or alternative procedures
Blank positive confirmation
Respondent fills in amount
Higher than confirming stated amount
Lower response rate possible
Negative confirmation
Many small homogeneous balances, low RMM, low expected exceptions, recipients likely to respond
Lower
Silence is evidence only under appropriate conditions
Bank confirmation
Cash, loans, collateral, arrangements
High
Confirms more than cash balance
A/R confirmation
Receivable existence and rights
High for existence
Does not prove collectability
A/P confirmation
Completeness, terms
Sometimes useful
Vendors with zero balances may be more useful than recorded balances
Notes and examples
Confirmations
Type
Meaning
Best use
Positive confirmation
Recipient responds whether agrees or disagrees
Higher risk, large balances, expected errors
Blank confirmation
Recipient fills in amount/info
More persuasive but lower response rate
Negative confirmation
Recipient responds only if disagrees
Low risk, many small balances, strong controls
If a positive confirmation is not returned, the auditor should perform follow-up and alternative procedures, such as examining subsequent cash receipts and supporting documents.
Analytical Procedures and Ratios
Analytical procedures are required during planning and final overall review in an audit. They may also be used as substantive procedures when suitably precise.
Ratio / measure
Plain formula
Audit interpretation
Current ratio
Current assets / Current liabilities
Liquidity; going-concern indicators
Quick ratio
Quick assets / Current liabilities
More conservative liquidity measure
Gross margin %
Gross profit / Net sales
Revenue, COGS, inventory valuation issues
Receivables turnover
Net credit sales / Average A/R
Collection speed and collectability
Days sales outstanding
365 / Receivables turnover
Higher DSO may indicate collectability or cutoff issues
Inventory turnover
COGS / Average inventory
Obsolescence, overstocking, costing issues
Days in inventory
365 / Inventory turnover
Slow movement may signal valuation issues
Debt-to-equity
Total liabilities / Equity
Leverage, covenant risk
Interest coverage
Income before interest and taxes / Interest expense
Auditor evaluates competence, capabilities, objectivity, and work
Component auditor communication
Group audits
Group auditor decides whether to make reference or assume responsibility
Notes and examples
Management Representation Letter
Representation area
Why it matters
Management responsibility for F/S
Confirms management, not auditor, owns statements
Completeness of information
Supports access to records and minutes
Fraud and suspected fraud
Required corroborative representation
Uncorrected misstatements
Management acknowledges effects
Litigation and claims
Supports legal contingency evaluation
Subsequent events
Confirms events through report date
Related parties
Supports completeness and disclosure
With Management and Those Charged With Governance
Communication
Usually to
Planned scope and timing
Those charged with governance
Significant findings
Those charged with governance
Significant accounting policies and estimates
Those charged with governance
Significant difficulties or disagreements
Those charged with governance
Uncorrected misstatements
Management and governance
Significant deficiencies and material weaknesses
Management and governance, usually in writing
Illegal acts or fraud involving senior management
Those charged with governance
Predecessor and Successor Auditor
Before accepting an engagement, the successor auditor asks management for permission to communicate with the predecessor. Topics include:
Management integrity.
Disagreements with management.
Reasons for auditor change.
Communications about fraud, noncompliance, or internal control matters.
Common trap: If management refuses permission, that is a major red flag for acceptance.
Subsequent Events and Subsequently Discovered Facts
Period
Auditor responsibility
Report dating choice
Balance sheet date to audit report date
Perform subsequent events procedures
Report date not earlier than sufficient evidence date
After report date but before report release
No active search duty, but investigate facts that come to attention
Dual date for specific event or extend date for all procedures
After report release
No active search duty, but act if facts existed at report date and report may be affected
Notify appropriate parties; consider revised report or user notification
Event type
Accounting treatment
Type I recognized subsequent event
Conditions existed at balance sheet date; adjust F/S
Type II nonrecognized subsequent event
Conditions arose after balance sheet date; disclose if material
Going-concern issue
Evaluate conditions and management plans; report implications depend on disclosure adequacy
Going Concern
Situation
Auditor response
Conditions raise substantial doubt
Perform additional procedures and evaluate management’s plans
Substantial doubt alleviated by management plans
Consider disclosure adequacy
Substantial doubt remains and disclosure is adequate
Unmodified opinion with required going-concern wording/section
Disclosure is inadequate
GAAP departure; qualified or adverse opinion depending materiality/pervasiveness
Management refuses assessment or evidence unavailable
Possible scope limitation
Common indicators: recurring losses, negative cash flows, loan defaults, denial of trade credit, legal proceedings, loss of major customer, uninsured catastrophe, work stoppage.
Notes and examples
Going Concern
The auditor evaluates whether substantial doubt exists about the entity’s ability to continue as a going concern for a reasonable period under applicable standards.
Situation
Audit reporting effect
Substantial doubt alleviated by management plans
Consider disclosure; unmodified opinion if adequate
Substantial doubt remains, disclosure adequate
Unmodified opinion with appropriate going-concern emphasis
Disclosure inadequate
Qualified or adverse opinion, depending on materiality/pervasiveness
Auditor cannot obtain sufficient evidence
Scope limitation; possible qualified opinion or disclaimer
Common trap: Going concern uncertainty does not automatically mean adverse opinion. The key is whether the financial statements and disclosures are appropriate.
Audit Reporting: Opinion Decisions
Issue
Material but not pervasive
Material and pervasive
GAAP departure
Qualified opinion
Adverse opinion
Scope limitation
Qualified opinion
Disclaimer of opinion
Inadequate going-concern disclosure
Qualified opinion
Adverse opinion
Lack of independence
Do not issue standard audit opinion; disclaimer or withdrawal depending circumstances
Do not issue standard audit opinion; disclaimer or withdrawal depending circumstances
Notes and examples
Report Modification Terms
Term
Use when
Core meaning
Unmodified opinion
Sufficient appropriate evidence and F/S fairly presented
Clean opinion
Qualified opinion
Material issue but not pervasive
“Except for”
Adverse opinion
Material and pervasive GAAP departure
F/S not fairly presented
Disclaimer of opinion
Auditor cannot obtain sufficient appropriate evidence and possible effects are pervasive
No opinion expressed
Emphasis-of-matter
Matter is properly presented/disclosed but fundamental to users’ understanding
Does not modify opinion
Other-matter
Matter not presented/disclosed in F/S but relevant to audit/report/users
Does not modify opinion
Emphasis-of-Matter vs Other-Matter
Paragraph
Matter location
Examples
Emphasis-of-matter
In the financial statements or notes
Major catastrophe, significant subsequent event, related-party transaction, special purpose framework
Other-matter
Outside the financial statements
Prior-period statements audited by predecessor, restricted use, required supplementary information issues
Issuer vs Nonissuer Reporting Distinctions
Area
Nonissuer audit
Issuer audit
Main auditing standards
AICPA GAAS / AU-C
PCAOB standards
Independence baseline
AICPA Code; other rules may apply
SEC/PCAOB independence rules
Report addressee
Often board, owners, or management
Often shareholders and board
Critical audit matters
Not generally required under AICPA GAAS
Included when required by PCAOB reporting rules
Internal control reporting
Separate engagement unless required by other rules
Integrated audit may include ICFR opinion
Terminology
Generally accepted auditing standards
Standards of the PCAOB
Notes and examples
Issuer vs Nonissuer Reporting: Quick Distinctions
Area
Nonissuer audits
Issuer audits
Standards
AICPA auditing standards
PCAOB standards
Opinion terminology
Unmodified opinion
Unqualified opinion commonly used in PCAOB context
Key audit matters / CAMs
Not the same as issuer CAM requirements
Critical audit matters may apply
Independence
AICPA and applicable rules
SEC/PCAOB independence considerations may apply
Internal control over financial reporting
Separate reporting only in certain contexts
Integrated audit concepts are important
Common trap: Do not mix report elements from one standard-setter into the other unless the question facts support it.
Group Audits and Component Auditors
Group auditor decision
Meaning
Reporting effect
Assume responsibility for component auditor
Group auditor is responsible for component work
No reference to component auditor
Make reference to component auditor
Responsibility is divided for component
Report refers to component auditor and magnitude of portion audited
Component auditor not independent or work inadequate
Group auditor cannot use work as planned
Perform additional procedures or modify approach
High-yield distinction: making reference is not a scope limitation by itself. It indicates divided responsibility.
Special Purpose Frameworks and Other Presentations
Presentation
Audit focus
Reporting point
Cash basis
Cash receipts/disbursements and related disclosures
Report identifies special purpose framework
Tax basis
Tax reporting principles
Users must understand framework
Regulatory basis
Regulator-prescribed accounting
May require restricted-use language depending purpose
Contractual basis
Agreement-prescribed accounting
Often restricted to parties to contract
Single financial statement or element
Specific statement/account
Materiality relates to the element
Supplementary information
Presented with audited F/S
“In relation to” opinion possible if procedures performed
Required supplementary information
Required by framework but outside basic F/S
Limited procedures; no opinion
SSARS: Preparation, Compilation, Review
Service
Assurance
Independence required?
Procedures
Report
Preparation
None
No
Prepare F/S from client information
No assurance indication on statements or disclaimer
Compilation
None
No, but disclose if not independent
Read F/S for obvious issues; no verification
Compilation report
Review
Limited
Yes
Inquiry and analytical procedures
Review report with limited assurance conclusion
SSARS Traps
Trap
Correct exam treatment
Compilation gives limited assurance
Incorrect; compilation gives no assurance
Review requires tests of controls
Incorrect; review primarily uses inquiry and analytics
Preparation requires independence
Incorrect
Lack of independence prevents compilation
Incorrect; disclose lack of independence
Review report expresses an opinion
Incorrect; it expresses a conclusion
Notes and examples
SSARS: Preparation, Compilation, Review
Service
Independence required?
Assurance
Report?
Main procedures
Preparation
No
None
No report required
Prepare financial statements
Compilation
No, but impairment disclosed
None
Yes
Read financial statements for obvious issues
Review
Yes
Limited
Yes
Inquiry and analytical procedures
SSARS Traps
Compilation does not provide assurance.
Review does not provide an opinion.
Preparation is not an attest service.
Lack of independence can be disclosed in a compilation, but not in a review.
Review evidence is much less extensive than audit evidence.
SSAE: Attestation Engagements
Engagement
Assurance
Practitioner work
Report language
Examination
Reasonable
Obtain sufficient evidence to support opinion
Opinion
Review
Limited
Inquiry, analytics, other limited procedures
Conclusion
Agreed-upon procedures
None
Perform specified procedures
Findings only
Compliance examination
Reasonable
Test compliance with specified requirements
Opinion
Prospective F/S examination
Reasonable
Evaluate assumptions and presentation
Opinion on conformity with guidelines and assumptions
Prospective F/S compilation
None
Assemble information; limited procedures
No assurance
Forecast vs Projection
Item
Forecast
Projection
Basis
Management’s expected financial results
Hypothetical assumptions
Use
Broader use may be appropriate
Often limited use
Key risk
Reasonableness of expected assumptions
Clear identification of hypothetical assumptions
Exam clue
“Best estimate”
“What-if” or hypothetical scenario
Notes and examples
SSAE Attestation Engagements
Engagement
Assurance
Report output
Examination
Reasonable
Opinion
Review
Limited
Conclusion
Agreed-upon procedures
None
Findings
Attestation Essentials
Subject matter must be capable of evaluation.
Suitable criteria are required.
Practitioner independence is generally required.
Management or responsible party is responsible for the subject matter.
AUP reports present procedures and findings, not assurance.
Common trap: In an agreed-upon procedures engagement, the practitioner does not decide whether the subject matter is fairly stated. Users evaluate the findings.
Independence and Ethics
Area
Rule of thumb
Common trap
Direct financial interest in attest client
Impairs independence
Materiality does not save a direct interest
Material indirect financial interest
Impairs independence
Immaterial indirect interest may not impair under AICPA rules
Management responsibilities
CPA cannot perform them for attest client
Preparing source docs or authorizing transactions impairs
Nonattest services
May be allowed for some clients if safeguards met
Management must accept responsibility and have suitable skill/knowledge/experience
Bookkeeping for audit client
May impair unless safeguards and limits satisfied; issuer rules are stricter
Do not apply nonissuer flexibility to issuer clients
Contingent fees
Generally prohibited for attest clients in relevant circumstances
Tax refund claims and attest clients are common test areas
Commissions/referral fees
Restricted for attest clients; disclosure may be required when allowed
Independence and disclosure are separate issues
Gifts/entertainment
Threat if more than clearly insignificant
“Customary” is not automatic approval
Employment with client
Key team member employment negotiations create threat
Remove from engagement and evaluate prior work if needed
Unpaid fees
May impair if significant and unpaid for extended period
Treated like a loan in substance
Notes and examples
Conceptual Framework Threats
Threat
Meaning
Example safeguard
Self-review
CPA audits own work
Separate personnel; avoid prohibited services
Advocacy
CPA promotes client position
Do not advocate in ways impairing objectivity
Adverse interest
CPA and client are opposed
Remove conflicted personnel
Familiarity
Too close to client
Rotation, independent review
Undue influence
Client pressure affects judgment
Governance communication, firm consultation
Financial self-interest
CPA benefits financially
Dispose of interest; remove individual
Management participation
CPA acts as management
Prohibited for attest client
Use of Specialists, Internal Auditors, and Service Organizations
Resource
Auditor responsibility
Key exam point
Auditor’s specialist
Evaluate competence, capabilities, objectivity; understand work
Auditor may refer to specialist only in limited reporting contexts
Management’s specialist
Evaluate specialist and data/assumptions used
Specialist’s work is audit evidence, not a substitute for auditor judgment
Internal auditors
May use work or direct assistance if appropriate
External auditor remains responsible for opinion
Service organization
Understand user entity controls and complementary user controls
SOC 1 reports are relevant to financial reporting controls
SOC 1 Type 1
Design and implementation at a point in time
Less evidence than Type 2 for operating effectiveness
SOC 1 Type 2
Design, implementation, and operating effectiveness over a period
More useful when relying on controls
Notes and examples
Specialist
The auditor may use a specialist for valuation, actuarial estimates, environmental obligations, complex instruments, or other specialized areas.
Evaluate:
Competence.
Capability.
Objectivity.
Work performed and assumptions used.
Relevance and reasonableness of findings.
Internal Auditors
The external auditor may use internal audit work when appropriate, but evaluates:
Objectivity.
Competence.
Systematic and disciplined approach.
Nature and risk of the area.
More judgmental or high-risk areas require more direct external auditor work.
Group Audits
For group audits, the group auditor considers:
Component significance.
Component auditor competence and independence.
Group-wide controls.
Consolidation process.
Communication with component auditors.
Common trap: The group auditor cannot simply outsource responsibility without evaluating the work and determining the effect on the group audit.
Government Auditing and Single Audit Concepts
Area
High-yield distinction
GAGAS / Yellow Book
Adds requirements beyond GAAS, including reporting on internal control and compliance in many audits
Independence
Emphasizes conceptual framework and threats from nonaudit services
Compliance
Auditor considers laws, regulations, contracts, and grant agreements relevant to audit objectives
Findings
Must be developed with condition, criteria, cause, effect, and recommendation when applicable
Single Audit
Focuses on federal awards, Schedule of Expenditures of Federal Awards, major programs, and compliance requirements
Reporting
May include reports on F/S, internal control, compliance, and schedule-related information
High-Yield “If You See This, Think That” Table
Exam clue
Think
“Recorded sales may be fictitious”
Vouch sales; confirm A/R; occurrence/existence
“Liabilities may be omitted”
Search for unrecorded liabilities; completeness
“Inventory held on consignment”
Rights and obligations; exclude if not owned
“Client refuses attorney letter”
Scope limitation
“Management refuses representation letter”
Scope limitation, possible disclaimer/withdrawal
“Substantial doubt adequately disclosed”
Unmodified opinion with going-concern language
“Substantial doubt not disclosed”
GAAP departure; qualified/adverse
“Scope limitation imposed by client”
Qualified/disclaimer or withdrawal depending severity
“Departure from GAAP is pervasive”
Adverse opinion
“Unable to obtain evidence; possible effects pervasive”
Disclaimer
“Review engagement”
Inquiry and analytical procedures; limited assurance
“Compilation engagement”
No assurance; independence disclosure if impaired
“AUP engagement”
Findings only; no assurance
“Projection”
Hypothetical assumptions; often limited use
“Component auditor referenced”
Divided responsibility, not scope limitation
“Negative confirmations only”
Appropriate only for low-risk, many small homogeneous accounts
“Substantive analytics for significant risk”
Usually need stronger, specifically responsive procedures
Common CPA AUD Traps
Trap
Correct answer logic
Audit provides absolute assurance
Audit provides reasonable assurance
Auditor guarantees no fraud exists
Auditor obtains reasonable assurance about material misstatement, including fraud
Strong controls eliminate substantive testing
Some substantive procedures are still required for material classes/accounts/disclosures
Control risk can be reduced without testing controls
No; operating effectiveness must be tested
Walkthrough equals test of operating effectiveness
Not necessarily; walkthrough primarily supports understanding/design/implementation
Confirmations prove valuation
They mainly prove existence/rights; collectability needs separate work
Management representation letter is primary evidence
It is required but corroborative
Analytical procedures alone are enough for high-risk assertions
It prevents review, but compilation may be performed with disclosure
Final Review Checklist
Before exam day, be able to answer quickly:
Which standard applies: AICPA GAAS, PCAOB, SSARS, SSAE, or GAGAS?
Is the engagement providing reasonable, limited, or no assurance?
Which assertion is tested by vouching, tracing, confirmation, recalculation, observation, or inquiry?
Does the issue involve a GAAP departure or a scope limitation?
Is the issue material only or material and pervasive?
Does the report need qualified, adverse, disclaimer, emphasis-of-matter, or other-matter wording?
Are controls being merely understood, or is operating effectiveness being tested?
Is the candidate answer confusing review, compilation, and preparation?
Are issuer rules being mixed up with nonissuer rules?
Is the question asking for the most persuasive evidence, not just any evidence?
Notes and examples
Final Review Checklist Before Practice
Before starting mixed AUD mock exams, confirm you can answer these quickly:
Which standards apply: GAAS, PCAOB, SSARS, SSAE, government/compliance?
What assurance level is provided?
What assertion is being tested?
Is the procedure a risk assessment, test of control, substantive test, or analytical procedure?
Is the evidence sufficient and appropriate?
Does the issue affect independence?
Is the misstatement material? Pervasive?
Is the issue a GAAP departure or a scope limitation?
Does the report need modification, emphasis, or other-matter language?
Are management representations required but not sufficient by themselves?
Is the event Type I or Type II?
Is the service organization report Type 1 or Type 2?
Is the sampling question about controls or dollar misstatement?
CPA AUD Cheat Sheet
This independent quick review is for candidates preparing for the AICPA U.S. CPA AUD - Auditing and Attestation exam, code CPA AUD. Use it as a final-pass review before moving into topic drills, mock exams, and detailed explanations in an independent companion practice question bank.
The AUD mindset is not “memorize every report.” It is:
Identify the engagement type.
Identify the applicable standards.
Decide the level of assurance.
Evaluate evidence, risk, materiality, and independence.
Choose the correct report or modification.
AUD Exam Mindset: The Core Decision Pattern
Most CPA AUD questions test professional judgment through a small set of recurring decisions.
Question asks about…
First decision
Common trap
Audit procedure
Which assertion?
Picking a strong procedure that tests the wrong assertion
Report wording
What engagement and opinion?
Confusing audit, review, compilation, examination, and agreed-upon procedures
Risk response
Is control reliance planned?
Testing controls when the auditor will not rely on them
Independence
Is the person a covered member / attest team / able to influence?
Assuming disclosure cures independence impairment
Misstatement
Material? Pervasive?
Treating all material issues as adverse opinions
Subsequent events
Type I recognized or Type II disclosed?
Adjusting for events that only provide new conditions
Internal control
Deficiency, significant deficiency, or material weakness?
Calling every control problem a material weakness
Sampling
Controls or substantive testing?
Mixing attribute sampling and variables sampling logic
Assurance Levels: Know the Engagement Before Answering
Engagement
Standards area
Assurance level
Primary procedures
Report language concept
Financial statement audit
GAAS / PCAOB as applicable
Reasonable assurance
Risk assessment, controls if relied on, substantive procedures
Opinion
Review of historical financial statements
SSARS for nonissuers in certain contexts
Limited assurance
Inquiry and analytical procedures
“Not aware of material modifications”
Compilation
SSARS
No assurance
Assist in presenting financial information
No opinion or conclusion
Preparation of financial statements
SSARS
No assurance
Prepare statements
No report required, but statements need no-assurance indication
Examination attestation
SSAE
Reasonable assurance
Evidence to support opinion on subject matter/assertion
Opinion
Review attestation
SSAE
Limited assurance
Inquiry, analytical, limited procedures
Conclusion
Agreed-upon procedures
SSAE
No assurance
Procedures agreed to by specified parties or users
Before accepting or continuing an audit, the auditor considers:
Independence and ethical requirements.
Management integrity.
Competence and availability of engagement team.
Whether the financial reporting framework is acceptable.
Whether management acknowledges its responsibilities.
Whether scope limitations are likely.
Communication with predecessor auditor when applicable.
Engagement Letter: What It Usually Covers
Engagement letter item
Why it matters
Objective and scope of audit
Prevents misunderstanding
Auditor responsibilities
Audit provides reasonable, not absolute, assurance
Management responsibilities
FS, internal control, access, representations
Applicable financial reporting framework
Defines criteria for fair presentation
Expected report form
May change if circumstances require
Use of specialists, internal auditors, component auditors
Clarifies responsibilities
Fees and logistics
Administrative but still important
Common trap: The auditor does not accept responsibility for preventing fraud or maintaining internal control. Those are management responsibilities.
Materiality: How AUD Questions Use It
Materiality is judged from the perspective of a reasonable user. It includes quantitative and qualitative factors.
Concept
Meaning
Exam use
Overall materiality
Materiality for financial statements as a whole
Planning benchmark
Performance materiality / tolerable misstatement
Lower amount used to reduce aggregation risk
Testing accounts/classes
Clearly trivial threshold
Items not accumulated
Evaluation efficiency
Qualitative materiality
Nature of item makes it important
Fraud, covenants, trends, related parties, compliance
Common Qualitative Red Flags
Turns a loss into income.
Helps meet analyst, lender, or bonus targets.
Masks a trend.
Affects debt covenant compliance.
Involves fraud or illegal acts.
Affects related-party disclosures.
Concerns a sensitive estimate or significant disclosure.
Assertions: Match Procedure to Objective
Transaction Assertions
Assertion
What can go wrong?
Common procedures
Occurrence
Recorded transaction did not happen
Vouch sales invoice to shipping document/order
Completeness
Transaction omitted
Trace shipping docs/receiving reports to records
Accuracy
Amount incorrect
Recalculate invoice, compare price/quantity
Cutoff
Wrong period
Test transactions around period-end
Classification
Wrong account
Inspect coding/chart of accounts
Presentation
Not properly presented/disclosed
Review disclosure requirements
Notes and examples
Account Balance Assertions
Assertion
What can go wrong?
Common procedures
Existence
Asset/liability does not exist
Confirm receivables, observe inventory
Rights and obligations
Entity does not own asset or owe liability
Inspect title, contracts, confirmations
Completeness
Asset/liability omitted
Search for unrecorded liabilities
Accuracy, valuation, allocation
Incorrect amount or valuation
Test pricing, estimates, allowances
Classification
Current/noncurrent or account classification wrong
Review terms and agreements
Presentation
Disclosure incomplete or unclear
Review notes and framework requirements
Directional Testing
Audit concern
Direction
Example
Existence / occurrence
From accounting records to source evidence
Vouch recorded sales to shipping docs
Completeness
From source evidence to accounting records
Trace shipping docs to sales journal
Overstatement
Vouch
Recorded amount may not be valid
Understatement
Trace
Valid item may not be recorded
Common trap: Confirming accounts receivable primarily tests existence, not completeness.
Testing Controls vs Substantive Procedures
flowchart TD
A[Assess risk of material misstatement] --> B{Plan to rely on controls?}
B -->|Yes| C[Test design and operating effectiveness]
C --> D{Controls effective?}
D -->|Yes| E[Reduce substantive testing as appropriate]
D -->|No| F[Increase substantive procedures]
B -->|No| G[Perform substantive procedures]
A --> H{Substantive procedures alone insufficient?}
H -->|Yes| C
When Tests of Controls Are Needed
Auditor plans to rely on controls.
Substantive procedures alone cannot provide sufficient appropriate evidence.
Compliance or integrated audit requirements apply.
Inquiry alone is rarely sufficient for testing operating effectiveness.
Fraud: High-Yield Review
Fraud includes fraudulent financial reporting and misappropriation of assets.
Fraud triangle element
Meaning
Example
Incentive/pressure
Motivation to commit fraud
Debt covenant pressure
Opportunity
Ability to commit/conceal fraud
Weak segregation of duties
Rationalization
Justification
“We will fix it next quarter”
Required Fraud Mindset
Maintain professional skepticism.
Discuss fraud risks with engagement team.
Inquire of management, internal audit, and others.
Consider management override.
Evaluate unusual journal entries.
Review accounting estimates for bias.
Consider whether revenue recognition presents a fraud risk.
Common trap: An audit is designed to obtain reasonable assurance, not to guarantee fraud detection.
Management Override: Typical Responses
High-yield procedures include:
Test journal entries and other adjustments.
Review accounting estimates for bias.
Evaluate business rationale for significant unusual transactions.
Consider related-party transactions.
Incorporate unpredictability into audit procedures.
Sampling: Fast Rules
Control Sampling
Concept
Attribute sampling
Used for
Tests of controls
Measures
Deviation rate
Key risk
Overreliance on ineffective controls
If deviations exceed tolerable rate
Do not rely as planned; increase substantive testing
Notes and examples
Substantive Sampling
Concept
Variables / monetary-unit sampling
Used for
Tests of details
Measures
Monetary misstatement
Key risk
Incorrect acceptance of materially misstated balance
If projected misstatement exceeds tolerable misstatement
Expand testing, request adjustment, or modify approach
Sampling Risk Effects
Risk
Affects
Meaning
Risk of assessing control risk too low
Effectiveness
Auditor relies too much on bad controls
Risk of assessing control risk too high
Efficiency
Auditor does extra work
Risk of incorrect acceptance
Effectiveness
Auditor accepts misstated balance
Risk of incorrect rejection
Efficiency
Auditor rejects fairly stated balance
Sample Size Direction
Change
Sample size effect
Higher desired confidence
Increase
Lower tolerable deviation/misstatement
Increase
Higher expected deviation/misstatement
Increase
Greater population variability
Increase
Larger population, after a point
Usually limited effect
Monetary-Unit Sampling Trap
Monetary-unit sampling is efficient for detecting overstatements in populations with recorded book values. It is less effective for understatements, zero balances, or negative balances.
Written Representations
Written representations are required audit evidence but do not replace other procedures.
Common representations include:
Management responsibility for financial statements.
Management responsibility for internal control.
All relevant information and access provided.
Disclosure of fraud or suspected fraud.
Disclosure of known noncompliance.
Related-party relationships and transactions disclosed.
Subsequent events evaluated.
Uncorrected misstatements acknowledged.
Common trap: Refusal to provide written representations is a serious scope limitation and may affect the auditor’s ability to issue an opinion.
Attorney Letters, Contingencies, and Litigation
Area
Auditor focus
Pending litigation
Existence, likelihood, estimate
Claims and assessments
Completeness and disclosure
Attorney response
Corroborates management’s information
Refusal to permit inquiry
Scope limitation
Unasserted claims
Often depend on management’s assessment and legal advice
Loss contingency accounting generally depends on likelihood and estimability. AUD questions often test whether the auditor has enough evidence and whether disclosure is adequate.
Related Parties
Related-party transactions are not automatically improper, but they require careful evaluation.
High-yield procedures:
Inquire of management and governance.
Inspect minutes, contracts, and conflict-of-interest statements.
Review unusual transactions.
Confirm terms with related parties when appropriate.
Evaluate business purpose.
Ensure proper disclosure.
Common trap: A transaction with a related party may need disclosure even if recorded at the correct amount.
Subsequent Events
Type
Condition existed at balance sheet date?
Financial statement treatment
Type I recognized event
Yes
Adjust financial statements
Type II nonrecognized event
No
Disclose if material; do not adjust
Subsequent Events Periods
Period
Auditor responsibility
Balance sheet date to auditor report date
Perform subsequent events procedures
After report date but before report release
No active search, but respond to facts discovered
After report release
Consider whether users need notification or revised statements
Common trap: If a subsequent event provides evidence about conditions existing at year-end, it usually affects recognition. If it relates to new conditions after year-end, it usually affects disclosure.
Audit Reports: Opinion Modifications
Issue
Material but not pervasive
Material and pervasive
GAAP departure / misstatement
Qualified opinion
Adverse opinion
Scope limitation / insufficient evidence
Qualified opinion
Disclaimer of opinion
Opinion Types
Opinion
When used
Unmodified / unqualified
Financial statements are presented fairly, in all material respects
Qualified
Except for a material issue, statements are fairly presented
Adverse
Financial statements are materially and pervasively misstated
Matter appropriately presented/disclosed in financial statements
No
Other-matter
Matter not presented/disclosed in financial statements but relevant to users’ understanding
No
Examples of emphasis matters may include going concern, significant uncertainty, or a major subsequent event when properly disclosed. The exact placement and wording depend on the applicable standards and report type.
Integrated Audit and ICFR Concepts
For audits involving internal control over financial reporting:
Concept
Key point
ICFR objective
Reasonable assurance about reliable financial reporting
Material weakness
Results in adverse opinion on ICFR
Significant deficiency
Communicated, but not necessarily adverse ICFR opinion
FS opinion vs ICFR opinion
Can differ
Control testing
Focuses on design and operating effectiveness
Entity-level controls
May have broad impact on audit approach
Common trap: An adverse ICFR opinion does not automatically mean the financial statement opinion is adverse. The auditor may still obtain enough substantive evidence for an unmodified financial statement opinion.
Service Organizations and SOC Reports
Report
Covers
Auditor use
SOC 1 Type 1
Design of controls at a point in time
Helps understand controls; does not support operating effectiveness over a period
SOC 1 Type 2
Design and operating effectiveness over a period
May support control reliance
Complementary user entity controls
Controls the user entity must have in place
Auditor evaluates whether user controls are designed/operating
Common trap: A SOC report does not eliminate the user auditor’s responsibility to understand the user entity’s controls and assess risk.
Prospective Financial Information
Type
Meaning
Forecast
Expected financial results based on expected conditions/actions
Projection
Hypothetical assumptions, often for a limited purpose
High-yield points:
Prospective information is not historical fact.
Assumptions are central to the engagement.
Reports avoid guaranteeing future results.
Projections often require careful attention to purpose and user limitations.
Government Auditing and Compliance Concepts
For government and compliance-oriented audits, AUD candidates should recognize:
Concept
Review point
Government auditing standards
Add requirements beyond a standard financial statement audit
Compliance audit
Tests compliance with laws, regulations, grants, or contracts
Internal control over compliance
Controls designed to prevent/detect noncompliance
Findings
Often include criteria, condition, cause, effect, and recommendation
Material noncompliance
May affect report conclusions and required communications
Common trap: Compliance reporting is not the same as a standard financial statement opinion, even when performed alongside a financial statement audit.
IT and Data Concepts
Modern AUD questions may include automated systems, IT general controls, and audit data analytics.