CPA AUD Cheat Sheet: Auditing and Attestation Cheat Sheet

Cheat sheet: CPA AUD reference for audit risk, evidence, reporting, ethics, attestations, reviews, compilations, and high-yield AICPA exam distinctions.


Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context

For AUD questions, think in this order:

  1. What engagement is being performed? Audit, review, compilation, preparation, examination, agreed-upon procedures, issuer audit, nonissuer audit, government audit.
  2. What standard applies? AICPA GAAS, PCAOB, SSARS, SSAE, GAGAS, or special reporting guidance.
  3. What assertion or objective is at risk? Existence, completeness, valuation, rights/obligations, cutoff, classification, presentation.
  4. What evidence is most persuasive? External, direct, written, original, generated under strong controls.
  5. What report wording or modification follows? Unmodified, qualified, adverse, disclaimer, emphasis-of-matter, other-matter, restricted-use, no assurance.

For CPA AUD, quick review only helps if you immediately apply it. After reading a section:

  1. Do focused topic drills on that area.
  2. Review detailed explanations for both correct and incorrect answers.
  3. Track whether mistakes are due to standards knowledge, assertion matching, report selection, or wording traps.
  4. Rework missed questions after a delay.
  5. Move to mixed sets only after individual weak areas improve.

A practical next step is to use an independent companion practice question bank with original practice questions, topic drills, mock exams, and detailed explanations focused on AICPA U.S. CPA AUD - Auditing and Attestation (CPA AUD).

Standards and Engagement Selection

Engagement / subject matterCommon standardsAssurance levelPractitioner outputHigh-yield exam point
Audit of nonissuer historical financial statementsAICPA GAAS / AU-CReasonable assuranceOpinion on whether F/S are fairly presentedAuditor obtains sufficient appropriate evidence; not absolute assurance
Audit of issuer financial statementsPCAOB auditing standardsReasonable assuranceOpinion under PCAOB reporting modelIssuer audits have PCAOB reporting and independence requirements
Integrated audit of issuer F/S and ICFRPCAOBReasonable assurance on bothOpinions on F/S and internal control over financial reportingMaterial weakness in ICFR requires adverse ICFR opinion
Review of nonissuer historical F/SSSARSLimited assuranceConclusion: not aware of material modificationsPrimarily inquiry and analytical procedures; no opinion
Compilation of nonissuer F/SSSARSNo assuranceCompilation reportIndependence not required, but lack of independence must be disclosed
Preparation of F/SSSARSNo assurancePrepared statements, generally no reportEach page should indicate no assurance or disclaimer is required
Examination of subject matter or assertionSSAE / AT-CReasonable assuranceOpinionSimilar assurance level to an audit, but on non-F/S subject matter
Attestation reviewSSAE / AT-CLimited assuranceConclusionLess evidence than examination; more than compilation
Agreed-upon proceduresSSAE / AT-CNo assuranceProcedures and findingsPractitioner does not conclude; users draw conclusions
Prospective financial informationSSAE / AT-CVaries by serviceExamination, compilation, or AUP reportForecast = expected results; projection = hypothetical assumptions
Government auditGAGAS, sometimes Single Audit rulesVariesAudit report plus compliance/internal control reportingAdds public accountability, compliance, and reporting considerations

Audit Risk Model

\[ \text{Audit Risk (AR)} = \text{Risk of Material Misstatement (RMM)} \times \text{Detection Risk (DR)} \]\[ \text{Risk of Material Misstatement (RMM)} = \text{Inherent Risk (IR)} \times \text{Control Risk (CR)} \]
ConceptMeaningExam use
Audit riskRisk auditor issues inappropriate opinion when F/S are materially misstatedOverall risk to manage through planning and evidence
Inherent riskSusceptibility to misstatement before considering controlsHigher for estimates, complex transactions, related parties, fraud incentives
Control riskRisk controls fail to prevent, detect, and correct misstatement timelyLower only if controls are designed, implemented, and operating effectively
Detection riskRisk audit procedures fail to detect material misstatementAuditor controls this through nature, timing, and extent of procedures
RMMCombined inherent and control riskAssessed at financial statement and assertion levels
Significant riskRisk requiring special audit considerationRequires tailored response; usually not addressed by analytical procedures alone
Notes and examples

Detection Risk Relationship

If assessed RMM is…Acceptable detection risk is…Auditor response
HigherLowerMore persuasive evidence, larger samples, more year-end testing, more experienced staff
LowerHigherLess extensive procedures may be acceptable if justified
Control risk assessed below maximumDepends on control testing resultsMust test operating effectiveness of controls
Controls not testedUsually maximum for relevant assertionsRely primarily on substantive procedures

Audit Risk Model

For audits, the auditor plans work to reduce audit risk to an acceptably low level.

\[ \text{Audit Risk} = \text{Risk of Material Misstatement} \times \text{Detection Risk} \]\[ \text{Risk of Material Misstatement} = \text{Inherent Risk} \times \text{Control Risk} \]
RiskMeaningAuditor controls it?Key response
Inherent riskSusceptibility before controlsNoUnderstand business, complexity, estimates, fraud risk
Control riskClient controls fail to prevent/detect/correctNoTest controls only if relying on them
Detection riskAuditor procedures fail to detect misstatementYesChange nature, timing, and extent of audit procedures
Audit riskAuditor gives inappropriate opinionIndirectlyLower detection risk when RMM is high

High-Yield Risk Relationship

If assessed RMM is…Detection risk should be…Evidence should be…
HigherLowerMore persuasive, often more year-end testing
LowerHigherLess extensive, but still sufficient and appropriate

Common trap: Higher inherent/control risk does not mean higher detection risk. It means the auditor must accept lower detection risk and perform stronger procedures.

Materiality Cheat Sheet

TermPractical meaningCommon trap
Overall materialityAmount that could influence users’ decisions on F/S as a wholeNot the same as tolerable misstatement
Performance materialityLower amount used to reduce risk that aggregate misstatements exceed overall materialityUsed to plan nature, timing, extent
Tolerable misstatementMaximum misstatement accepted in a population during samplingApplied to specific account/class testing
Clearly trivial thresholdAmount below which misstatements need not be accumulatedNot a free pass for qualitative issues
Qualitative materialitySmall amount may be material due to natureFraud, covenant compliance, trend reversal, related-party concealment

Audit Process Map

PhaseKey actionsCommon AUD focus
Acceptance / continuanceIndependence, competence, integrity, engagement terms, predecessor communicationPermission needed before predecessor responds
PlanningStrategy, audit plan, team discussion, materiality, preliminary analyticsPlanning is iterative, not one-time
Risk assessmentUnderstand entity, environment, controls, fraud risks, significant risksProcedures identify risk; they do not provide sufficient evidence alone
Internal control evaluationUnderstand design and implementation; test operating effectiveness if relying on controlsWalkthroughs help confirm understanding
Further audit proceduresTests of controls, substantive analytical procedures, tests of detailsLink procedures to assertions
CompletionSubsequent events, going concern, misstatement evaluation, representation letter, reviewManagement representation letter does not replace other evidence
ReportingForm opinion, modify if needed, add required sections/paragraphsSeparate GAAP departures from scope limitations

Assertions and Best-Fit Procedures

AssertionApplies toWhat can go wrongBest-fit procedure examples
ExistenceAssets, liabilities, equityRecorded item does not existConfirm receivables; inspect securities; observe inventory
OccurrenceTransactions/eventsRecorded transaction did not occurVouch sales to shipping docs/customer orders
CompletenessAccounts, transactions, disclosuresItem omittedTrace receiving reports to payables; search for unrecorded liabilities
Rights and obligationsAssets/liabilitiesEntity lacks rights or has unrecorded obligationsInspect title, contracts, debt agreements, leases
Valuation / allocationBalancesWrong amount, allowance, impairment, estimateRecalculate depreciation; test allowance; evaluate fair value inputs
AccuracyTransactions/disclosuresMath or recorded amount wrongRecalculate invoice extensions, payroll, interest
CutoffTransactionsRecorded in wrong periodTest shipping/receiving around year-end
ClassificationTransactions/accountsRecorded in wrong accountInspect coding, agreements, board minutes
PresentationF/S and disclosuresNot properly aggregated, described, or disclosedReview disclosures against framework and agreements
Notes and examples

Directional Testing

Audit directionStarts withEnds withPrimary assertionDetects
VouchAccounting recordsSource documentsExistence / occurrenceOverstatement
TraceSource documentsAccounting recordsCompletenessUnderstatement
RecalculateClient calculationAuditor mathAccuracy / valuationMathematical errors
Inspect subsequent cash disbursementsPost-year-end paymentsYear-end liability populationCompletenessUnrecorded liabilities
Confirm with third partyExternal partyAuditor directlyExistence, rights, obligationsFalse or misstated recorded balances

Evidence Reliability

Evidence characteristicMore reliableLess reliable
SourceIndependent external sourceInternal source
RouteSent directly to auditorPassed through client
FormWritten/electronic documentaryOral representation
SystemProduced under strong controlsProduced under weak controls
NatureOriginal documentCopy or scanned image
ProcedureAuditor recalculation/reperformanceInquiry alone

Inquiry alone is rarely sufficient appropriate audit evidence for a significant assertion.

Notes and examples

Evidence: Reliability Ranking

Evidence must be sufficient and appropriate. Sufficiency is quantity; appropriateness is relevance and reliability.

More reliableLess reliable
Direct auditor knowledgeClient-provided explanations
External evidence received directly by auditorExternal evidence routed through client
Original documentsCopies or scanned documents
Written evidenceOral evidence
Evidence from strong internal controlsEvidence from weak internal controls
Recalculation/reperformanceInquiry alone

Procedure Strengths and Weaknesses

ProcedureBest forLimitation
InquiryUnderstanding, corroboratingNot enough alone for important assertions
ObservationSeeing process performedOnly valid at observed time
InspectionDocuments/assetsDocuments may not prove ownership or valuation
ConfirmationExistence/rights/termsNonresponse requires follow-up
RecalculationMathematical accuracyDoes not prove underlying data is valid
ReperformanceControl effectivenessCan be time-consuming
Analytical proceduresRelationships/trendsLess persuasive for detailed assertions
ScanningUnusual itemsDepends on auditor judgment

Audit Procedures by Account Area

AreaKey risksCommon proceduresHigh-yield notes
CashExistence, restrictions, kiting, unrecorded debtBank confirmations, bank reconciliations, cutoff bank statement, proof of cashBank confirmations may reveal loans and collateral, not just balances
Accounts receivableExistence, valuation, cutoffPositive/negative confirmations, subsequent collections, allowance testing, sales cutoffConfirmations mainly test existence, not collectability
RevenueOccurrence, cutoff, fraudVouch sales, inspect contracts, cutoff testing, analytics, journal-entry testingRevenue recognition is a presumed fraud risk unless rebutted with support
InventoryExistence, valuation, cutoffObserve count, test counts, inspect condition, price/cost tests, lower of cost/NRVObservation supports existence and condition, not ownership by itself
Accounts payableCompletenessSearch for unrecorded liabilities, vendor statements, subsequent disbursementsConfirming A/P is less common; use vendor statements and unmatched receiving reports
Long-term debtCompleteness, classification, covenant disclosureConfirm debt, inspect agreements, recalculate interest, review covenantsDebt confirmation can identify collateral and terms
EquityAuthorization, classificationInspect board minutes, stock records, treasury stock activityFew transactions, high legal significance
PayrollOccurrence, accuracyReconcile payroll register, test rates, inspect HR authorizationsGhost employees are occurrence risk
EstimatesValuation, biasTest management process, develop independent estimate, review subsequent eventsManagement bias can be directional across estimates
Fair valueValuation, disclosureEvaluate model, inputs, specialist work, sensitivityLower-level inputs usually require more skepticism
Related partiesCompleteness, disclosure, business purposeInquire, inspect minutes/contracts, review unusual transactionsRisk is often concealment, not just measurement
Litigation/claimsCompleteness, disclosureAttorney letter, management inquiry, minutes reviewAttorney refusal or limitation may create scope limitation
Notes and examples

Revenue and Receivables

Risk/assertionStrong procedures
AR existencePositive confirmations, subsequent cash receipts
Sales occurrenceVouch recorded sales to shipping docs/orders
Sales completenessTrace shipping documents to sales invoices/journal
CutoffTest shipments around year-end
Allowance valuationAging analysis, subsequent collections, historical loss rates
Fraud riskJournal entries, side agreements, unusual terms

Common trap: Negative confirmations are appropriate only when risk is low, controls are effective, balances are small/homogeneous, and recipients are expected to respond if incorrect.

Inventory

Risk/assertionStrong procedures
Existence/conditionObserve physical count
CompletenessTrace floor counts to final inventory records
RightsInspect consignment/warehouse agreements
ValuationTest cost, lower of cost and net realizable value, obsolescence
CutoffTest receiving/shipping around year-end

If inventory observation is impracticable, the auditor performs alternative procedures. If sufficient evidence cannot be obtained, consider a scope limitation.

Purchases, Payables, and Expenses

Risk/assertionStrong procedures
AP completenessSearch for unrecorded liabilities
Expense cutoffReview receiving reports and vendor invoices around year-end
ValidityVouch recorded purchases to purchase orders/receiving reports
Accrued liabilitiesReview subsequent disbursements
Related partiesInspect board minutes, contracts, confirmations

Search for unrecorded liabilities usually focuses on understatement, so it starts with subsequent cash disbursements, unmatched receiving reports, vendor statements, and invoices.

Cash

Risk/assertionStrong procedures
ExistenceBank confirmations
CompletenessBank reconciliations, cutoff bank statements
KitingInterbank transfer schedule
RestrictionsReview agreements and disclosures
FraudSurprise counts, segregation of duties review

Payroll

Risk/assertionStrong procedures
OccurrenceCompare payroll to HR records/time approvals
CompletenessReconcile payroll tax filings to payroll records
AuthorizationInspect approval of pay rates
SegregationSeparate HR authorization, timekeeping, payroll processing, distribution

Debt and Equity

Risk/assertionStrong procedures
CompletenessConfirm debt with lenders, inspect board minutes
ClassificationReview maturity dates and covenant terms
ValuationRecalculate interest and amortization
DisclosureReview covenants, collateral, restrictions
Equity authorizationInspect minutes and shareholder records

Estimates and Fair Value

Risk/assertionStrong procedures
ReasonablenessEvaluate method, assumptions, and data
BiasRetrospective review of prior estimates
Specialist useEvaluate competence, capability, objectivity
Fair valueCompare to market data or independent pricing
DisclosureReview sensitivity and uncertainty disclosures

Common trap: The auditor does not simply accept management’s estimate because it is complex. Complexity often increases inherent risk.

Confirmations

Confirmation typeUse whenEvidence strengthCommon trap
Positive confirmationLarge balances, high risk, expected disputes, complex accountsHigherNonresponse requires follow-up or alternative procedures
Blank positive confirmationRespondent fills in amountHigher than confirming stated amountLower response rate possible
Negative confirmationMany small homogeneous balances, low RMM, low expected exceptions, recipients likely to respondLowerSilence is evidence only under appropriate conditions
Bank confirmationCash, loans, collateral, arrangementsHighConfirms more than cash balance
A/R confirmationReceivable existence and rightsHigh for existenceDoes not prove collectability
A/P confirmationCompleteness, termsSometimes usefulVendors with zero balances may be more useful than recorded balances
Notes and examples

Confirmations

TypeMeaningBest use
Positive confirmationRecipient responds whether agrees or disagreesHigher risk, large balances, expected errors
Blank confirmationRecipient fills in amount/infoMore persuasive but lower response rate
Negative confirmationRecipient responds only if disagreesLow risk, many small balances, strong controls

If a positive confirmation is not returned, the auditor should perform follow-up and alternative procedures, such as examining subsequent cash receipts and supporting documents.

Analytical Procedures and Ratios

Analytical procedures are required during planning and final overall review in an audit. They may also be used as substantive procedures when suitably precise.

Ratio / measurePlain formulaAudit interpretation
Current ratioCurrent assets / Current liabilitiesLiquidity; going-concern indicators
Quick ratioQuick assets / Current liabilitiesMore conservative liquidity measure
Gross margin %Gross profit / Net salesRevenue, COGS, inventory valuation issues
Receivables turnoverNet credit sales / Average A/RCollection speed and collectability
Days sales outstanding365 / Receivables turnoverHigher DSO may indicate collectability or cutoff issues
Inventory turnoverCOGS / Average inventoryObsolescence, overstocking, costing issues
Days in inventory365 / Inventory turnoverSlow movement may signal valuation issues
Debt-to-equityTotal liabilities / EquityLeverage, covenant risk
Interest coverageIncome before interest and taxes / Interest expenseGoing-concern and debt covenant analysis
Notes and examples
Unexpected trendPossible audit concern
Sales increase but cash collections decreaseFictitious sales, collectability, channel stuffing
Gross margin improves sharplyPremature revenue, understated COGS, inventory costing error
Inventory grows faster than salesObsolescence, overstatement, demand decline
A/P decreases while purchases increaseUnrecorded liabilities
Legal expense increasesLitigation disclosure risk
Repairs expense decreases while assets increaseImproper capitalization

Analytical Procedures

Audit phaseRequired or common?Purpose
PlanningExpectedUnderstand business, identify risks
Substantive testingOptionalObtain evidence if predictable relationships exist
Final reviewExpectedEvaluate overall financial statement reasonableness

Analytical procedures are strongest when:

  • Data is reliable.
  • Relationships are predictable.
  • Expectation is precise.
  • Difference threshold is appropriate.
  • Unexpected differences are investigated and corroborated.

Common trap: Inquiry alone does not resolve an unexpected analytical difference. The auditor needs corroborating evidence.

Internal Control Reference

COSO Components

ComponentWhat auditor considersExample
Control environmentTone at the top, integrity, governance oversightAudit committee oversight
Risk assessmentEntity process to identify and respond to risksNew system implementation risk analysis
Control activitiesPolicies/procedures that address risksApprovals, reconciliations, segregation of duties
Information and communicationRelevant information captured and communicatedReliable financial reporting system
MonitoringOngoing or separate evaluationsInternal audit reviews, control deficiency follow-up
Notes and examples

Control Testing

ProcedurePurpose
InquiryUnderstand how control is performed; weak alone
ObservationSee control being performed; limited to moment observed
InspectionExamine evidence of performance
ReperformanceAuditor independently executes control; strong evidence
WalkthroughTrace transaction through system to confirm understanding/design/implementation
If auditor plans to rely on controlsThen auditor must…
Reduce substantive testing based on controlsTest operating effectiveness
Assess control risk below maximumTest operating effectiveness
Perform integrated auditTest controls over financial reporting
Believe substantive procedures alone are insufficientTest relevant controls

Control Deficiency Severity

Deficiency typeMeaningCommunication
Control deficiencyControl missing or not operating such that misstatements may not be prevented/detected/corrected timelyCommunicate as appropriate
Significant deficiencyLess severe than material weakness but important enough for governance attentionWritten communication to management and those charged with governance
Material weaknessReasonable possibility material misstatement will not be prevented/detected/corrected timelyWritten communication; adverse ICFR opinion in integrated audit

Internal Control: COSO Components

ComponentWhat to remember
Control environmentTone at the top, integrity, governance, assignment of authority
Risk assessmentEntity identifies and responds to business/reporting risks
Control activitiesApprovals, reconciliations, segregation, physical controls, IT controls
Information and communicationCapturing, processing, reporting relevant information
MonitoringOngoing or separate evaluations of control performance

Control Deficiency Severity

TypeMeaningCommunication
Control deficiencyControl design or operation does not prevent/detect/correct misstatement timelyUsually management-level
Significant deficiencyImportant enough to merit attention by those charged with governanceCommunicate to governance
Material weaknessReasonable possibility material misstatement will not be prevented/detected/corrected timelyWritten communication to management and governance

Common trap: A material weakness means there is a reasonable possibility of material misstatement, not that a misstatement definitely occurred.

Fraud, Noncompliance, and Professional Skepticism

AreaAuditor responsibilityHigh-yield procedures
Fraud riskObtain reasonable assurance F/S are free of material misstatement due to fraud or errorBrainstorming, inquiries, analytics, journal-entry testing
Management overridePresumed fraud riskTest journal entries, review estimates for bias, evaluate significant unusual transactions
Revenue recognition fraudPresumed fraud risk unless rebuttedCutoff testing, contract review, confirmations, analytics
Misappropriation of assetsConsider incentives/opportunitiesCash, inventory, payroll, expense testing
Noncompliance with laws/regulationsConsider effect on F/SInquire, inspect correspondence, legal letters, minutes
Illegal acts with direct material effectTreat like other material misstatementsMore direct audit procedures
Illegal acts with indirect effectLimited responsibility unless information comes to attentionInquire and evaluate implications
Notes and examples

Fraud vs Error

FeatureErrorFraud
IntentUnintentionalIntentional
Common formMiscalculation, misunderstandingFraudulent reporting or asset misappropriation
Auditor challengeDetect material errorFraud may involve concealment, collusion, override
Reporting implicationCorrect or modify if materialConsider governance communication, legal implications, withdrawal where appropriate

Sampling Reference

Sampling conceptEffect on sample size
Higher desired confidenceIncreases sample size
Lower acceptable risk of incorrect acceptance / overrelianceIncreases sample size
Higher tolerable misstatement or deviation rateDecreases sample size
Higher expected misstatement or deviation rateIncreases sample size
Greater population variabilityIncreases variables sample size
Larger population sizeUsually limited effect after moderate size
Notes and examples
Sampling riskType of testEffect
Risk of overrelianceTest of controlsEffectiveness problem; auditor relies on ineffective control
Risk of underrelianceTest of controlsEfficiency problem; auditor does more work than needed
Risk of incorrect acceptanceSubstantive testEffectiveness problem; auditor accepts materially misstated balance
Risk of incorrect rejectionSubstantive testEfficiency problem; auditor investigates balance that is not materially misstated
Sampling typeUsed forOutput
Attribute samplingTests of controlsDeviation rate
Variables samplingSubstantive dollar testingEstimated misstatement
Monetary-unit samplingSubstantive testing, overstatement emphasisProbability proportional to size
Classical variables samplingSubstantive testingMean/difference/ratio estimates

Communications and Documentation

CommunicationTiming / audienceKey exam point
Engagement letterBefore or at start of engagement; management/TCWGEstablishes objective, responsibilities, framework, scope
Predecessor auditor inquiryBefore accepting, with client permissionAsk about integrity, disagreements, fraud, noncompliance, reasons for change
Those charged with governancePlanned scope/timing and significant findingsIncludes significant difficulties, disagreements, uncorrected misstatements
Management letterManagementMay include control observations and recommendations
Internal control deficienciesManagement and governance depending severitySignificant deficiencies and material weaknesses communicated in writing
Representation letterManagement, dated as of audit report dateRefusal is scope limitation
Attorney letterSent by management to external counselCounsel response supports litigation/claims evaluation
Specialist communicationWhen using auditor’s or management’s specialistAuditor evaluates competence, capabilities, objectivity, and work
Component auditor communicationGroup auditsGroup auditor decides whether to make reference or assume responsibility
Notes and examples

Management Representation Letter

Representation areaWhy it matters
Management responsibility for F/SConfirms management, not auditor, owns statements
Completeness of informationSupports access to records and minutes
Fraud and suspected fraudRequired corroborative representation
Uncorrected misstatementsManagement acknowledges effects
Litigation and claimsSupports legal contingency evaluation
Subsequent eventsConfirms events through report date
Related partiesSupports completeness and disclosure

With Management and Those Charged With Governance

CommunicationUsually to
Planned scope and timingThose charged with governance
Significant findingsThose charged with governance
Significant accounting policies and estimatesThose charged with governance
Significant difficulties or disagreementsThose charged with governance
Uncorrected misstatementsManagement and governance
Significant deficiencies and material weaknessesManagement and governance, usually in writing
Illegal acts or fraud involving senior managementThose charged with governance

Predecessor and Successor Auditor

Before accepting an engagement, the successor auditor asks management for permission to communicate with the predecessor. Topics include:

  • Management integrity.
  • Disagreements with management.
  • Reasons for auditor change.
  • Communications about fraud, noncompliance, or internal control matters.

Common trap: If management refuses permission, that is a major red flag for acceptance.

Subsequent Events and Subsequently Discovered Facts

PeriodAuditor responsibilityReport dating choice
Balance sheet date to audit report datePerform subsequent events proceduresReport date not earlier than sufficient evidence date
After report date but before report releaseNo active search duty, but investigate facts that come to attentionDual date for specific event or extend date for all procedures
After report releaseNo active search duty, but act if facts existed at report date and report may be affectedNotify appropriate parties; consider revised report or user notification
Event typeAccounting treatment
Type I recognized subsequent eventConditions existed at balance sheet date; adjust F/S
Type II nonrecognized subsequent eventConditions arose after balance sheet date; disclose if material
Going-concern issueEvaluate conditions and management plans; report implications depend on disclosure adequacy

Going Concern

SituationAuditor response
Conditions raise substantial doubtPerform additional procedures and evaluate management’s plans
Substantial doubt alleviated by management plansConsider disclosure adequacy
Substantial doubt remains and disclosure is adequateUnmodified opinion with required going-concern wording/section
Disclosure is inadequateGAAP departure; qualified or adverse opinion depending materiality/pervasiveness
Management refuses assessment or evidence unavailablePossible scope limitation

Common indicators: recurring losses, negative cash flows, loan defaults, denial of trade credit, legal proceedings, loss of major customer, uninsured catastrophe, work stoppage.

Notes and examples

Going Concern

The auditor evaluates whether substantial doubt exists about the entity’s ability to continue as a going concern for a reasonable period under applicable standards.

SituationAudit reporting effect
Substantial doubt alleviated by management plansConsider disclosure; unmodified opinion if adequate
Substantial doubt remains, disclosure adequateUnmodified opinion with appropriate going-concern emphasis
Disclosure inadequateQualified or adverse opinion, depending on materiality/pervasiveness
Auditor cannot obtain sufficient evidenceScope limitation; possible qualified opinion or disclaimer

Common trap: Going concern uncertainty does not automatically mean adverse opinion. The key is whether the financial statements and disclosures are appropriate.

Audit Reporting: Opinion Decisions

IssueMaterial but not pervasiveMaterial and pervasive
GAAP departureQualified opinionAdverse opinion
Scope limitationQualified opinionDisclaimer of opinion
Inadequate going-concern disclosureQualified opinionAdverse opinion
Lack of independenceDo not issue standard audit opinion; disclaimer or withdrawal depending circumstancesDo not issue standard audit opinion; disclaimer or withdrawal depending circumstances
Notes and examples

Report Modification Terms

TermUse whenCore meaning
Unmodified opinionSufficient appropriate evidence and F/S fairly presentedClean opinion
Qualified opinionMaterial issue but not pervasive“Except for”
Adverse opinionMaterial and pervasive GAAP departureF/S not fairly presented
Disclaimer of opinionAuditor cannot obtain sufficient appropriate evidence and possible effects are pervasiveNo opinion expressed
Emphasis-of-matterMatter is properly presented/disclosed but fundamental to users’ understandingDoes not modify opinion
Other-matterMatter not presented/disclosed in F/S but relevant to audit/report/usersDoes not modify opinion

Emphasis-of-Matter vs Other-Matter

ParagraphMatter locationExamples
Emphasis-of-matterIn the financial statements or notesMajor catastrophe, significant subsequent event, related-party transaction, special purpose framework
Other-matterOutside the financial statementsPrior-period statements audited by predecessor, restricted use, required supplementary information issues

Issuer vs Nonissuer Reporting Distinctions

AreaNonissuer auditIssuer audit
Main auditing standardsAICPA GAAS / AU-CPCAOB standards
Independence baselineAICPA Code; other rules may applySEC/PCAOB independence rules
Report addresseeOften board, owners, or managementOften shareholders and board
Critical audit mattersNot generally required under AICPA GAASIncluded when required by PCAOB reporting rules
Internal control reportingSeparate engagement unless required by other rulesIntegrated audit may include ICFR opinion
TerminologyGenerally accepted auditing standardsStandards of the PCAOB
Notes and examples

Issuer vs Nonissuer Reporting: Quick Distinctions

AreaNonissuer auditsIssuer audits
StandardsAICPA auditing standardsPCAOB standards
Opinion terminologyUnmodified opinionUnqualified opinion commonly used in PCAOB context
Key audit matters / CAMsNot the same as issuer CAM requirementsCritical audit matters may apply
IndependenceAICPA and applicable rulesSEC/PCAOB independence considerations may apply
Internal control over financial reportingSeparate reporting only in certain contextsIntegrated audit concepts are important

Common trap: Do not mix report elements from one standard-setter into the other unless the question facts support it.

Group Audits and Component Auditors

Group auditor decisionMeaningReporting effect
Assume responsibility for component auditorGroup auditor is responsible for component workNo reference to component auditor
Make reference to component auditorResponsibility is divided for componentReport refers to component auditor and magnitude of portion audited
Component auditor not independent or work inadequateGroup auditor cannot use work as plannedPerform additional procedures or modify approach

High-yield distinction: making reference is not a scope limitation by itself. It indicates divided responsibility.

Special Purpose Frameworks and Other Presentations

PresentationAudit focusReporting point
Cash basisCash receipts/disbursements and related disclosuresReport identifies special purpose framework
Tax basisTax reporting principlesUsers must understand framework
Regulatory basisRegulator-prescribed accountingMay require restricted-use language depending purpose
Contractual basisAgreement-prescribed accountingOften restricted to parties to contract
Single financial statement or elementSpecific statement/accountMateriality relates to the element
Supplementary informationPresented with audited F/S“In relation to” opinion possible if procedures performed
Required supplementary informationRequired by framework but outside basic F/SLimited procedures; no opinion

SSARS: Preparation, Compilation, Review

ServiceAssuranceIndependence required?ProceduresReport
PreparationNoneNoPrepare F/S from client informationNo assurance indication on statements or disclaimer
CompilationNoneNo, but disclose if not independentRead F/S for obvious issues; no verificationCompilation report
ReviewLimitedYesInquiry and analytical proceduresReview report with limited assurance conclusion

SSARS Traps

TrapCorrect exam treatment
Compilation gives limited assuranceIncorrect; compilation gives no assurance
Review requires tests of controlsIncorrect; review primarily uses inquiry and analytics
Preparation requires independenceIncorrect
Lack of independence prevents compilationIncorrect; disclose lack of independence
Review report expresses an opinionIncorrect; it expresses a conclusion
Notes and examples

SSARS: Preparation, Compilation, Review

ServiceIndependence required?AssuranceReport?Main procedures
PreparationNoNoneNo report requiredPrepare financial statements
CompilationNo, but impairment disclosedNoneYesRead financial statements for obvious issues
ReviewYesLimitedYesInquiry and analytical procedures

SSARS Traps

  • Compilation does not provide assurance.
  • Review does not provide an opinion.
  • Preparation is not an attest service.
  • Lack of independence can be disclosed in a compilation, but not in a review.
  • Review evidence is much less extensive than audit evidence.

SSAE: Attestation Engagements

EngagementAssurancePractitioner workReport language
ExaminationReasonableObtain sufficient evidence to support opinionOpinion
ReviewLimitedInquiry, analytics, other limited proceduresConclusion
Agreed-upon proceduresNonePerform specified proceduresFindings only
Compliance examinationReasonableTest compliance with specified requirementsOpinion
Prospective F/S examinationReasonableEvaluate assumptions and presentationOpinion on conformity with guidelines and assumptions
Prospective F/S compilationNoneAssemble information; limited proceduresNo assurance

Forecast vs Projection

ItemForecastProjection
BasisManagement’s expected financial resultsHypothetical assumptions
UseBroader use may be appropriateOften limited use
Key riskReasonableness of expected assumptionsClear identification of hypothetical assumptions
Exam clue“Best estimate”“What-if” or hypothetical scenario
Notes and examples

SSAE Attestation Engagements

EngagementAssuranceReport output
ExaminationReasonableOpinion
ReviewLimitedConclusion
Agreed-upon proceduresNoneFindings

Attestation Essentials

  • Subject matter must be capable of evaluation.
  • Suitable criteria are required.
  • Practitioner independence is generally required.
  • Management or responsible party is responsible for the subject matter.
  • AUP reports present procedures and findings, not assurance.

Common trap: In an agreed-upon procedures engagement, the practitioner does not decide whether the subject matter is fairly stated. Users evaluate the findings.

Independence and Ethics

AreaRule of thumbCommon trap
Direct financial interest in attest clientImpairs independenceMateriality does not save a direct interest
Material indirect financial interestImpairs independenceImmaterial indirect interest may not impair under AICPA rules
Management responsibilitiesCPA cannot perform them for attest clientPreparing source docs or authorizing transactions impairs
Nonattest servicesMay be allowed for some clients if safeguards metManagement must accept responsibility and have suitable skill/knowledge/experience
Bookkeeping for audit clientMay impair unless safeguards and limits satisfied; issuer rules are stricterDo not apply nonissuer flexibility to issuer clients
Contingent feesGenerally prohibited for attest clients in relevant circumstancesTax refund claims and attest clients are common test areas
Commissions/referral feesRestricted for attest clients; disclosure may be required when allowedIndependence and disclosure are separate issues
Gifts/entertainmentThreat if more than clearly insignificant“Customary” is not automatic approval
Employment with clientKey team member employment negotiations create threatRemove from engagement and evaluate prior work if needed
Unpaid feesMay impair if significant and unpaid for extended periodTreated like a loan in substance
Notes and examples

Conceptual Framework Threats

ThreatMeaningExample safeguard
Self-reviewCPA audits own workSeparate personnel; avoid prohibited services
AdvocacyCPA promotes client positionDo not advocate in ways impairing objectivity
Adverse interestCPA and client are opposedRemove conflicted personnel
FamiliarityToo close to clientRotation, independent review
Undue influenceClient pressure affects judgmentGovernance communication, firm consultation
Financial self-interestCPA benefits financiallyDispose of interest; remove individual
Management participationCPA acts as managementProhibited for attest client

Use of Specialists, Internal Auditors, and Service Organizations

ResourceAuditor responsibilityKey exam point
Auditor’s specialistEvaluate competence, capabilities, objectivity; understand workAuditor may refer to specialist only in limited reporting contexts
Management’s specialistEvaluate specialist and data/assumptions usedSpecialist’s work is audit evidence, not a substitute for auditor judgment
Internal auditorsMay use work or direct assistance if appropriateExternal auditor remains responsible for opinion
Service organizationUnderstand user entity controls and complementary user controlsSOC 1 reports are relevant to financial reporting controls
SOC 1 Type 1Design and implementation at a point in timeLess evidence than Type 2 for operating effectiveness
SOC 1 Type 2Design, implementation, and operating effectiveness over a periodMore useful when relying on controls
Notes and examples

Specialist

The auditor may use a specialist for valuation, actuarial estimates, environmental obligations, complex instruments, or other specialized areas.

Evaluate:

  • Competence.
  • Capability.
  • Objectivity.
  • Work performed and assumptions used.
  • Relevance and reasonableness of findings.

Internal Auditors

The external auditor may use internal audit work when appropriate, but evaluates:

  • Objectivity.
  • Competence.
  • Systematic and disciplined approach.
  • Nature and risk of the area.

More judgmental or high-risk areas require more direct external auditor work.

Group Audits

For group audits, the group auditor considers:

  • Component significance.
  • Component auditor competence and independence.
  • Group-wide controls.
  • Consolidation process.
  • Communication with component auditors.

Common trap: The group auditor cannot simply outsource responsibility without evaluating the work and determining the effect on the group audit.

Government Auditing and Single Audit Concepts

AreaHigh-yield distinction
GAGAS / Yellow BookAdds requirements beyond GAAS, including reporting on internal control and compliance in many audits
IndependenceEmphasizes conceptual framework and threats from nonaudit services
ComplianceAuditor considers laws, regulations, contracts, and grant agreements relevant to audit objectives
FindingsMust be developed with condition, criteria, cause, effect, and recommendation when applicable
Single AuditFocuses on federal awards, Schedule of Expenditures of Federal Awards, major programs, and compliance requirements
ReportingMay include reports on F/S, internal control, compliance, and schedule-related information

High-Yield “If You See This, Think That” Table

Exam clueThink
“Recorded sales may be fictitious”Vouch sales; confirm A/R; occurrence/existence
“Liabilities may be omitted”Search for unrecorded liabilities; completeness
“Inventory held on consignment”Rights and obligations; exclude if not owned
“Client refuses attorney letter”Scope limitation
“Management refuses representation letter”Scope limitation, possible disclaimer/withdrawal
“Substantial doubt adequately disclosed”Unmodified opinion with going-concern language
“Substantial doubt not disclosed”GAAP departure; qualified/adverse
“Scope limitation imposed by client”Qualified/disclaimer or withdrawal depending severity
“Departure from GAAP is pervasive”Adverse opinion
“Unable to obtain evidence; possible effects pervasive”Disclaimer
“Review engagement”Inquiry and analytical procedures; limited assurance
“Compilation engagement”No assurance; independence disclosure if impaired
“AUP engagement”Findings only; no assurance
“Projection”Hypothetical assumptions; often limited use
“Component auditor referenced”Divided responsibility, not scope limitation
“Negative confirmations only”Appropriate only for low-risk, many small homogeneous accounts
“Substantive analytics for significant risk”Usually need stronger, specifically responsive procedures

Common CPA AUD Traps

TrapCorrect answer logic
Audit provides absolute assuranceAudit provides reasonable assurance
Auditor guarantees no fraud existsAuditor obtains reasonable assurance about material misstatement, including fraud
Strong controls eliminate substantive testingSome substantive procedures are still required for material classes/accounts/disclosures
Control risk can be reduced without testing controlsNo; operating effectiveness must be tested
Walkthrough equals test of operating effectivenessNot necessarily; walkthrough primarily supports understanding/design/implementation
Confirmations prove valuationThey mainly prove existence/rights; collectability needs separate work
Management representation letter is primary evidenceIt is required but corroborative
Analytical procedures alone are enough for high-risk assertionsUsually not sufficient
All subsequent events require adjustmentOnly Type I events generally require adjustment
Emphasis-of-matter modifies opinionIt does not modify the opinion
Review report expresses positive assuranceReview provides limited/negative assurance style conclusion
Compilation requires verificationCompilation does not verify information
Lack of independence always prevents SSARS workIt prevents review, but compilation may be performed with disclosure

Final Review Checklist

Before exam day, be able to answer quickly:

  • Which standard applies: AICPA GAAS, PCAOB, SSARS, SSAE, or GAGAS?
  • Is the engagement providing reasonable, limited, or no assurance?
  • Which assertion is tested by vouching, tracing, confirmation, recalculation, observation, or inquiry?
  • Does the issue involve a GAAP departure or a scope limitation?
  • Is the issue material only or material and pervasive?
  • Does the report need qualified, adverse, disclaimer, emphasis-of-matter, or other-matter wording?
  • Are controls being merely understood, or is operating effectiveness being tested?
  • Is the candidate answer confusing review, compilation, and preparation?
  • Are issuer rules being mixed up with nonissuer rules?
  • Is the question asking for the most persuasive evidence, not just any evidence?
Notes and examples

Final Review Checklist Before Practice

Before starting mixed AUD mock exams, confirm you can answer these quickly:

  • Which standards apply: GAAS, PCAOB, SSARS, SSAE, government/compliance?
  • What assurance level is provided?
  • What assertion is being tested?
  • Is the procedure a risk assessment, test of control, substantive test, or analytical procedure?
  • Is the evidence sufficient and appropriate?
  • Does the issue affect independence?
  • Is the misstatement material? Pervasive?
  • Is the issue a GAAP departure or a scope limitation?
  • Does the report need modification, emphasis, or other-matter language?
  • Are management representations required but not sufficient by themselves?
  • Is the event Type I or Type II?
  • Is the service organization report Type 1 or Type 2?
  • Is the sampling question about controls or dollar misstatement?

CPA AUD Cheat Sheet

This independent quick review is for candidates preparing for the AICPA U.S. CPA AUD - Auditing and Attestation exam, code CPA AUD. Use it as a final-pass review before moving into topic drills, mock exams, and detailed explanations in an independent companion practice question bank.

The AUD mindset is not “memorize every report.” It is:

  1. Identify the engagement type.
  2. Identify the applicable standards.
  3. Decide the level of assurance.
  4. Evaluate evidence, risk, materiality, and independence.
  5. Choose the correct report or modification.

AUD Exam Mindset: The Core Decision Pattern

Most CPA AUD questions test professional judgment through a small set of recurring decisions.

Question asks about…First decisionCommon trap
Audit procedureWhich assertion?Picking a strong procedure that tests the wrong assertion
Report wordingWhat engagement and opinion?Confusing audit, review, compilation, examination, and agreed-upon procedures
Risk responseIs control reliance planned?Testing controls when the auditor will not rely on them
IndependenceIs the person a covered member / attest team / able to influence?Assuming disclosure cures independence impairment
MisstatementMaterial? Pervasive?Treating all material issues as adverse opinions
Subsequent eventsType I recognized or Type II disclosed?Adjusting for events that only provide new conditions
Internal controlDeficiency, significant deficiency, or material weakness?Calling every control problem a material weakness
SamplingControls or substantive testing?Mixing attribute sampling and variables sampling logic

Assurance Levels: Know the Engagement Before Answering

EngagementStandards areaAssurance levelPrimary proceduresReport language concept
Financial statement auditGAAS / PCAOB as applicableReasonable assuranceRisk assessment, controls if relied on, substantive proceduresOpinion
Review of historical financial statementsSSARS for nonissuers in certain contextsLimited assuranceInquiry and analytical procedures“Not aware of material modifications”
CompilationSSARSNo assuranceAssist in presenting financial informationNo opinion or conclusion
Preparation of financial statementsSSARSNo assurancePrepare statementsNo report required, but statements need no-assurance indication
Examination attestationSSAEReasonable assuranceEvidence to support opinion on subject matter/assertionOpinion
Review attestationSSAELimited assuranceInquiry, analytical, limited proceduresConclusion
Agreed-upon proceduresSSAENo assuranceProcedures agreed to by specified parties or usersFindings only, no opinion/conclusion
Notes and examples

Quick rule: Audit/examination = reasonable assurance. Review = limited assurance. Compilation/preparation/AUP = no assurance.

Planning and Engagement Acceptance

Before accepting or continuing an audit, the auditor considers:

  • Independence and ethical requirements.
  • Management integrity.
  • Competence and availability of engagement team.
  • Whether the financial reporting framework is acceptable.
  • Whether management acknowledges its responsibilities.
  • Whether scope limitations are likely.
  • Communication with predecessor auditor when applicable.

Engagement Letter: What It Usually Covers

Engagement letter itemWhy it matters
Objective and scope of auditPrevents misunderstanding
Auditor responsibilitiesAudit provides reasonable, not absolute, assurance
Management responsibilitiesFS, internal control, access, representations
Applicable financial reporting frameworkDefines criteria for fair presentation
Expected report formMay change if circumstances require
Use of specialists, internal auditors, component auditorsClarifies responsibilities
Fees and logisticsAdministrative but still important

Common trap: The auditor does not accept responsibility for preventing fraud or maintaining internal control. Those are management responsibilities.

Materiality: How AUD Questions Use It

Materiality is judged from the perspective of a reasonable user. It includes quantitative and qualitative factors.

ConceptMeaningExam use
Overall materialityMateriality for financial statements as a wholePlanning benchmark
Performance materiality / tolerable misstatementLower amount used to reduce aggregation riskTesting accounts/classes
Clearly trivial thresholdItems not accumulatedEvaluation efficiency
Qualitative materialityNature of item makes it importantFraud, covenants, trends, related parties, compliance

Common Qualitative Red Flags

  • Turns a loss into income.
  • Helps meet analyst, lender, or bonus targets.
  • Masks a trend.
  • Affects debt covenant compliance.
  • Involves fraud or illegal acts.
  • Affects related-party disclosures.
  • Concerns a sensitive estimate or significant disclosure.

Assertions: Match Procedure to Objective

Transaction Assertions

AssertionWhat can go wrong?Common procedures
OccurrenceRecorded transaction did not happenVouch sales invoice to shipping document/order
CompletenessTransaction omittedTrace shipping docs/receiving reports to records
AccuracyAmount incorrectRecalculate invoice, compare price/quantity
CutoffWrong periodTest transactions around period-end
ClassificationWrong accountInspect coding/chart of accounts
PresentationNot properly presented/disclosedReview disclosure requirements
Notes and examples

Account Balance Assertions

AssertionWhat can go wrong?Common procedures
ExistenceAsset/liability does not existConfirm receivables, observe inventory
Rights and obligationsEntity does not own asset or owe liabilityInspect title, contracts, confirmations
CompletenessAsset/liability omittedSearch for unrecorded liabilities
Accuracy, valuation, allocationIncorrect amount or valuationTest pricing, estimates, allowances
ClassificationCurrent/noncurrent or account classification wrongReview terms and agreements
PresentationDisclosure incomplete or unclearReview notes and framework requirements

Directional Testing

Audit concernDirectionExample
Existence / occurrenceFrom accounting records to source evidenceVouch recorded sales to shipping docs
CompletenessFrom source evidence to accounting recordsTrace shipping docs to sales journal
OverstatementVouchRecorded amount may not be valid
UnderstatementTraceValid item may not be recorded

Common trap: Confirming accounts receivable primarily tests existence, not completeness.

Testing Controls vs Substantive Procedures

    flowchart TD
	    A[Assess risk of material misstatement] --> B{Plan to rely on controls?}
	    B -->|Yes| C[Test design and operating effectiveness]
	    C --> D{Controls effective?}
	    D -->|Yes| E[Reduce substantive testing as appropriate]
	    D -->|No| F[Increase substantive procedures]
	    B -->|No| G[Perform substantive procedures]
	    A --> H{Substantive procedures alone insufficient?}
	    H -->|Yes| C

When Tests of Controls Are Needed

  • Auditor plans to rely on controls.
  • Substantive procedures alone cannot provide sufficient appropriate evidence.
  • Compliance or integrated audit requirements apply.
  • Controls address high-volume automated processing.

Control Testing Procedures

ProcedureUse
InquiryAsk personnel how control is performed
ObservationWatch control being performed
InspectionReview evidence of control performance
ReperformanceAuditor independently performs the control

Inquiry alone is rarely sufficient for testing operating effectiveness.

Fraud: High-Yield Review

Fraud includes fraudulent financial reporting and misappropriation of assets.

Fraud triangle elementMeaningExample
Incentive/pressureMotivation to commit fraudDebt covenant pressure
OpportunityAbility to commit/conceal fraudWeak segregation of duties
RationalizationJustification“We will fix it next quarter”

Required Fraud Mindset

  • Maintain professional skepticism.
  • Discuss fraud risks with engagement team.
  • Inquire of management, internal audit, and others.
  • Consider management override.
  • Evaluate unusual journal entries.
  • Review accounting estimates for bias.
  • Consider whether revenue recognition presents a fraud risk.

Common trap: An audit is designed to obtain reasonable assurance, not to guarantee fraud detection.

Management Override: Typical Responses

High-yield procedures include:

  • Test journal entries and other adjustments.
  • Review accounting estimates for bias.
  • Evaluate business rationale for significant unusual transactions.
  • Consider related-party transactions.
  • Incorporate unpredictability into audit procedures.

Sampling: Fast Rules

Control Sampling

ConceptAttribute sampling
Used forTests of controls
MeasuresDeviation rate
Key riskOverreliance on ineffective controls
If deviations exceed tolerable rateDo not rely as planned; increase substantive testing
Notes and examples

Substantive Sampling

ConceptVariables / monetary-unit sampling
Used forTests of details
MeasuresMonetary misstatement
Key riskIncorrect acceptance of materially misstated balance
If projected misstatement exceeds tolerable misstatementExpand testing, request adjustment, or modify approach

Sampling Risk Effects

RiskAffectsMeaning
Risk of assessing control risk too lowEffectivenessAuditor relies too much on bad controls
Risk of assessing control risk too highEfficiencyAuditor does extra work
Risk of incorrect acceptanceEffectivenessAuditor accepts misstated balance
Risk of incorrect rejectionEfficiencyAuditor rejects fairly stated balance

Sample Size Direction

ChangeSample size effect
Higher desired confidenceIncrease
Lower tolerable deviation/misstatementIncrease
Higher expected deviation/misstatementIncrease
Greater population variabilityIncrease
Larger population, after a pointUsually limited effect

Monetary-Unit Sampling Trap

Monetary-unit sampling is efficient for detecting overstatements in populations with recorded book values. It is less effective for understatements, zero balances, or negative balances.

Written Representations

Written representations are required audit evidence but do not replace other procedures.

Common representations include:

  • Management responsibility for financial statements.
  • Management responsibility for internal control.
  • All relevant information and access provided.
  • Disclosure of fraud or suspected fraud.
  • Disclosure of known noncompliance.
  • Related-party relationships and transactions disclosed.
  • Subsequent events evaluated.
  • Uncorrected misstatements acknowledged.

Common trap: Refusal to provide written representations is a serious scope limitation and may affect the auditor’s ability to issue an opinion.

Attorney Letters, Contingencies, and Litigation

AreaAuditor focus
Pending litigationExistence, likelihood, estimate
Claims and assessmentsCompleteness and disclosure
Attorney responseCorroborates management’s information
Refusal to permit inquiryScope limitation
Unasserted claimsOften depend on management’s assessment and legal advice

Loss contingency accounting generally depends on likelihood and estimability. AUD questions often test whether the auditor has enough evidence and whether disclosure is adequate.

Related-party transactions are not automatically improper, but they require careful evaluation.

High-yield procedures:

  • Inquire of management and governance.
  • Inspect minutes, contracts, and conflict-of-interest statements.
  • Review unusual transactions.
  • Confirm terms with related parties when appropriate.
  • Evaluate business purpose.
  • Ensure proper disclosure.

Common trap: A transaction with a related party may need disclosure even if recorded at the correct amount.

Subsequent Events

TypeCondition existed at balance sheet date?Financial statement treatment
Type I recognized eventYesAdjust financial statements
Type II nonrecognized eventNoDisclose if material; do not adjust

Subsequent Events Periods

PeriodAuditor responsibility
Balance sheet date to auditor report datePerform subsequent events procedures
After report date but before report releaseNo active search, but respond to facts discovered
After report releaseConsider whether users need notification or revised statements

Common trap: If a subsequent event provides evidence about conditions existing at year-end, it usually affects recognition. If it relates to new conditions after year-end, it usually affects disclosure.

Audit Reports: Opinion Modifications

IssueMaterial but not pervasiveMaterial and pervasive
GAAP departure / misstatementQualified opinionAdverse opinion
Scope limitation / insufficient evidenceQualified opinionDisclaimer of opinion

Opinion Types

OpinionWhen used
Unmodified / unqualifiedFinancial statements are presented fairly, in all material respects
QualifiedExcept for a material issue, statements are fairly presented
AdverseFinancial statements are materially and pervasively misstated
DisclaimerAuditor cannot obtain sufficient appropriate evidence, or independence issue prevents opinion

Emphasis-of-Matter vs Other-Matter

ParagraphRefers toOpinion modified?
Emphasis-of-matterMatter appropriately presented/disclosed in financial statementsNo
Other-matterMatter not presented/disclosed in financial statements but relevant to users’ understandingNo

Examples of emphasis matters may include going concern, significant uncertainty, or a major subsequent event when properly disclosed. The exact placement and wording depend on the applicable standards and report type.

Integrated Audit and ICFR Concepts

For audits involving internal control over financial reporting:

ConceptKey point
ICFR objectiveReasonable assurance about reliable financial reporting
Material weaknessResults in adverse opinion on ICFR
Significant deficiencyCommunicated, but not necessarily adverse ICFR opinion
FS opinion vs ICFR opinionCan differ
Control testingFocuses on design and operating effectiveness
Entity-level controlsMay have broad impact on audit approach

Common trap: An adverse ICFR opinion does not automatically mean the financial statement opinion is adverse. The auditor may still obtain enough substantive evidence for an unmodified financial statement opinion.

Service Organizations and SOC Reports

ReportCoversAuditor use
SOC 1 Type 1Design of controls at a point in timeHelps understand controls; does not support operating effectiveness over a period
SOC 1 Type 2Design and operating effectiveness over a periodMay support control reliance
Complementary user entity controlsControls the user entity must have in placeAuditor evaluates whether user controls are designed/operating

Common trap: A SOC report does not eliminate the user auditor’s responsibility to understand the user entity’s controls and assess risk.

Prospective Financial Information

TypeMeaning
ForecastExpected financial results based on expected conditions/actions
ProjectionHypothetical assumptions, often for a limited purpose

High-yield points:

  • Prospective information is not historical fact.
  • Assumptions are central to the engagement.
  • Reports avoid guaranteeing future results.
  • Projections often require careful attention to purpose and user limitations.

Government Auditing and Compliance Concepts

For government and compliance-oriented audits, AUD candidates should recognize:

ConceptReview point
Government auditing standardsAdd requirements beyond a standard financial statement audit
Compliance auditTests compliance with laws, regulations, grants, or contracts
Internal control over complianceControls designed to prevent/detect noncompliance
FindingsOften include criteria, condition, cause, effect, and recommendation
Material noncomplianceMay affect report conclusions and required communications

Common trap: Compliance reporting is not the same as a standard financial statement opinion, even when performed alongside a financial statement audit.

IT and Data Concepts

Modern AUD questions may include automated systems, IT general controls, and audit data analytics.

IT areaWhat to know
General IT controlsAccess, change management, operations, backup/recovery
Application controlsInput, processing, output controls within an application
Automated controlsConsistent if programmed correctly, but depend on ITGCs
Access controlsPrevent unauthorized transactions or changes
Change managementPrevent unauthorized program changes
Audit data analyticsCan identify anomalies, trends, duplicates, gaps, or unusual relationships

Common trap: A strong automated application control may still be unreliable if relevant general IT controls are weak.

Common AUD Candidate Mistakes

MistakeBetter approach
Memorizing reports without understanding engagement typeFirst identify audit, review, compilation, examination, or AUP
Choosing inquiry as sufficient evidenceInquiry usually needs corroboration
Confusing completeness and existenceCompleteness traces from source to records; existence vouches from records to source
Treating materiality as only numericalConsider qualitative factors
Assuming all control deficiencies are material weaknessesEvaluate likelihood and magnitude
Forgetting pervasivenessMaterial/pervasive drives adverse vs qualified or disclaimer vs qualified
Mixing SSARS and SSAESSARS is for certain financial statement services; SSAE is attestation
Overlooking independenceIndependence impairment often cannot be fixed by disclosure
Ignoring management responsibilitiesManagement owns FS, internal control, and representations
Thinking high risk means fewer proceduresHigh RMM means stronger evidence and lower detection risk

Fast Opinion Modification Drill

Use this decision table when practicing report questions.

StepAskResult
1Is the auditor independent?If no, disclaimer or do not accept/continue depending on facts
2Is there sufficient appropriate evidence?If no, scope limitation
3Are financial statements materially misstated?If yes, GAAP departure/misstatement
4Is the effect material?If no, unmodified may still be appropriate
5Is the effect pervasive?Drives adverse/disclaimer vs qualified
6Is disclosure adequate?Inadequate disclosure can cause qualified/adverse opinion
7Is emphasis needed without modifying opinion?Consider emphasis-of-matter or other-matter

Put the review into practice