CPA Exam — Auditing and Attestation (AUD) — All Questions
111 questions
Maria, a staff auditor on the engagement team for the audit of Crane Co., a nonissuer, inherits Crane shares worth $900, an amount immaterial to her. She obtains the right to sell the shares on March 3. Under the AICPA Code of Professional Conduct, what must happen for her independence not to be impaired?
- a.She tells the engagement partner about the shares and keeps them, since they are immaterial
- b.She transfers the shares to her spouse before the auditor's report is issued
- c.She keeps the shares until the auditor's report is released and then sells them
- d.She disposes of the shares within 30 days after she obtains the right to dispose of them✓
The Unsolicited Financial Interests interpretation (ET 1.240.020) accepts an inherited interest only if the covered member disposes of it as soon as practicable and no later than 30 days after gaining knowledge of it and the right to dispose of it. Materiality does not matter for a direct financial interest: ET 1.240.010 says any direct interest held during the period of the professional engagement impairs independence, so telling the partner does not cure it. A spouse is immediate family, whose interests are treated as the covered member's own, and holding the shares until the report is released keeps a direct interest during the engagement period.
A CPA firm is about to issue its current-year audit report for a nonissuer client. The client still owes the firm a fee, significant to the firm, for tax services the firm performed 14 months before the report date. Under the AICPA Code, which conclusion follows?
- a.Independence is impaired unless the fee is paid before the report is issued✓
- b.Independence is not impaired if the client signs a promissory note for the unpaid fee
- c.Independence is impaired only if the unpaid fee is for prior audit services
- d.Independence is not impaired if the unpaid fee is disclosed in the report
ET 1.230.010.03 says threats are not at an acceptable level if, when the current-year attest report is issued, unpaid fees are significant to the covered member and relate to services provided more than one year before the report date. The interpretation covers fees for any professional services, not only audit fees. It also states that unpaid fees include a note receivable arising from such fees, so signing a note changes nothing, and there is no provision for curing the threat by disclosure in the report.
The owner of a nonissuer audit client asks the audit firm to design the company's new payroll approval process. The owner says no one at the company has the time or knowledge to oversee the work and asks the firm to decide on the final design. Under the AICPA Code, what is the effect on independence?
- a.Not impaired, provided that a partner who is not on the audit team does the work
- b.Impaired, since management cannot oversee the work or take responsibility for it✓
- c.Not impaired, as long as the firm documents the work in an engagement letter
- d.Impaired only if payroll expense is material to the financial statements as a whole
The general requirements for nonattest services (ET 1.295.040) require management to designate an individual with suitable skill, knowledge, or experience to oversee the service and to accept responsibility for its results. If the client cannot or will not do so, the member's performance of the service impairs independence. A written understanding is a separate required safeguard, not a substitute for management's responsibility, and having a different partner do the work does not change who makes the decisions. The rule contains no materiality exception.
Management of a nonissuer attest client sues its audit firm, alleging deficient audit work in the prior year. Under the AICPA Conceptual Framework for Independence, the lawsuit creates which type of threat?
- a.Management participation threat
- b.Familiarity threat
- c.Undue influence threat
- d.Adverse interest threat✓
ET 1.210.010.12 describes an adverse interest threat as one where the member's interests are opposed to the attest client's, and gives the client or member starting litigation against the other as its example. A familiarity threat comes from a long or close relationship. A management participation threat comes from taking on management's role. An undue influence threat arises when the member gives in to pressure or dominance, such as a threat to replace the firm.
A CPA in public practice wants to upload a client's general ledger to a cloud-based AI analytics tool operated by an outside vendor. Under the AICPA Code of Professional Conduct, what must the CPA do before disclosing the client's confidential information to the vendor?
- a.Tell the client after the engagement is finished that an outside vendor was used
- b.Obtain written approval from the state board of accountancy before uploading any data
- c.Get the client's consent, or bind the vendor by contract and verify its safeguards✓
- d.Nothing further, because a vendor assisting the CPA is treated as part of the CPA's firm
The interpretation on disclosing information to a third-party service provider (ET 1.700.040) requires one of two things before disclosure: specific consent from the client, or a contract requiring the provider to keep the information confidential together with reasonable assurance that the provider has procedures to prevent unauthorized release. A vendor is not treated as part of the firm. No state board approval is involved, and telling the client after the fact does not meet the requirement, which applies before disclosure.
A CPA firm audits the financial statements of Brook LLC, a nonissuer. Which fee arrangement for another service to Brook is permitted under the AICPA Code?
- a.A fee equal to 25% of the refund obtained through an amended tax return
- b.A consulting fee payable only if Brook's new bank loan is approved
- c.A consulting fee that varies with the complexity of the work performed✓
- d.A bonus payable only if Brook's sales rise 10% after a pricing study
The Contingent Fees Rule (ET 1.510.001) bars a member from performing any service for a contingent fee for a client whose financial statements the firm audits, and bars contingent fees for preparing an original or amended return or refund claim for any client. A fee paid only if the loan is approved, or only if sales reach a target, depends on a finding or result and is contingent. The rule states that fees may vary with the complexity of the services rendered, so that arrangement is permitted.
Lena, a CPA in public practice, compiles financial statements for Oak Corp. that she expects Oak's bank to use. Her compilation report discloses her lack of independence, and she performs no other attest services for Oak. A software vendor will pay her a commission if Oak buys its product on her recommendation. Under the AICPA Code, which statement is true?
- a.She may accept the commission only with the bank's written consent
- b.She may accept the commission with no disclosure, as she is not independent
- c.She may accept the commission but must disclose it to Oak✓
- d.She may not accept any commission, because Oak is her compilation client
The Commissions and Referral Fees Rule (ET 1.520.001.01) bars commissions from a client for whom the member performs an audit, a review, a compilation that a third party is expected to use when the report does not disclose a lack of independence, or an examination of prospective financial information. Lena's report discloses her lack of independence, so the prohibition does not apply. Paragraph .03 then requires her to disclose the permitted commission to the person to whom she recommends the product. The bank's consent plays no part in the rule.
Under the SEC's auditor independence rules (Regulation S-X Rule 2-01), a lead audit partner has served in that role on an issuer's audit for five consecutive years. When may that partner next serve as lead partner or engagement quality reviewer for this issuer?
- a.After a two-year time-out period
- b.Immediately, if the audit committee approves
- c.After a one-year time-out period
- d.After a five-year time-out period✓
Rule 2-01(c)(6)(i)(A)(1) limits the lead partner and the engagement quality reviewer to five consecutive years, and (c)(6)(i)(B)(1) bars the partner from either role for the five consecutive years that follow. A two-year time-out applies to other audit partners after seven years. One year is the employment cooling-off period in Rule 2-01(c)(2)(iii)(B), not a rotation period. Audit committee approval is not an exception; the only relief is for small firms whose engagements the PCAOB reviews every three years.
Jin worked about 300 hours as audit senior on the audit of Vega Corp., an issuer, during the year before audit procedures began for the fiscal period in which Vega hired him as its CFO. Under SEC Rule 2-01, what is the effect on the audit firm?
- a.The firm remains independent if Jin worked fewer than 500 hours on the audit
- b.The firm remains independent if Jin has no capital balance in the firm
- c.The firm is not independent of Vega✓
- d.The firm remains independent if a partner replaces Jin on the audit team
Rule 2-01(c)(2)(iii)(B) says a firm is not independent when a former engagement team member takes a financial reporting oversight role at an issuer unless that person was not on the audit engagement team during the one-year period before audit procedures began for the period that includes the hire date. Settling capital balances and financial arrangements is a separate condition in (c)(2)(iii)(A) and does not satisfy the cooling-off test. The only hours exception excludes people other than the lead partner and engagement quality reviewer who provided 10 or fewer hours, so 300 hours does not qualify. Staffing changes do not cure the problem.
An accounting firm audits Delta Inc., an issuer. Assuming the audit committee pre-approves it, which service could the firm provide to Delta without impairing independence under SEC Rule 2-01?
- a.Performing Delta's outsourced internal audit of financial controls
- b.Designing the software that generates Delta's sales ledger
- c.Valuing an acquired brand that Delta will record as an asset
- d.Preparing Delta's federal corporate income tax return✓
Rule 2-01(c)(4) lists the prohibited non-audit services. They include financial information systems design and implementation, internal audit outsourcing related to internal accounting controls, and appraisal or valuation services whose results will be subject to audit. Tax compliance work is not on that list. It is allowed when the audit committee pre-approves it under Rule 2-01(c)(7), subject to the PCAOB's separate tax-service rules.
Want these explained in order? CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
Under SEC Rule 2-01(c)(7), the audit committee's pre-approval requirement for a non-audit service by an issuer's auditor may be waived only if, among other conditions, all such services add up to no more than what share of the total fees paid by the client to its auditor for the fiscal year?
- a.1 percent
- b.15 percent
- c.10 percent
- d.5 percent✓
Rule 2-01(c)(7)(i)(C) allows the de minimis exception only when the aggregate amount of such services is no more than five percent of total revenues the audit client paid to its accountant during the fiscal year. The services also must not have been recognized as non-audit services when the engagement began, and they must be brought to the audit committee promptly and approved before the audit is completed. The other percentages do not appear in the rule.
Under the Department of Labor's interpretive bulletin on the independence of accountants who audit employee benefit plans, which circumstance would make the accountant not independent for the plan's audit?
- a.A member of the accounting firm maintains the plan's financial records✓
- b.A former sponsor employee now at the firm has fully cut ties and is off the plan audit
- c.An actuary associated with the firm provides actuarial services to the plan
- d.The firm is separately engaged by the plan sponsor for other professional work
The DOL bulletin (29 CFR 2509.2022-01, which the AICPA blueprint cites under its former number 2509.75-9) states in paragraph (b)(3) that an accountant is not independent if the accountant or a member of the firm maintains financial records for the plan. Paragraph (c)(1) says an accountant does not lose independence solely because the firm is engaged by the plan sponsor or because an associated actuary serves the plan. Paragraph (b)(2) exempts a former employee of the plan or sponsor who has completely disassociated and does not audit periods of his or her employment.
Under the 2024 revision of Government Auditing Standards, how much continuing professional education must an auditor who performs engagement procedures on a GAGAS engagement complete?
- a.40 hours every year, 12 of them in government auditing, with no carryover allowed
- b.120 hours every 3 years, with no government-related minimum and 20 hours in each year
- c.80 hours every 2 years, 24 of them government-related, and at least 20 hours in each year✓
- d.80 hours every 2 years, 56 of them government-related, and at least 10 hours in each year
Paragraph 4.16 of the 2024 Yellow Book requires at least 80 hours of CPE in every 2-year period: 24 hours on the government environment, government auditing, or the audited entity's specific environment, and 56 hours that enhance professional expertise. Paragraph 4.17 adds a minimum of 20 hours in each year of the 2-year period. The 120-hour and 40-hour patterns are not GAGAS rules, and the 56 hours are the general portion, not the government-specific one.
An audit organization that performs GAGAS engagements is not already subject to a peer review requirement. How often does the 2024 revision of Government Auditing Standards require it to obtain an external peer review?
- a.Only after issuing a modified report
- b.At least once every 3 years✓
- c.At least once every year
- d.At least once every 5 years
Paragraph 5.179 of the 2024 Yellow Book states that an audit organization not already subject to a peer review requirement should obtain an external peer review at least once every 3 years. The standard does not set an annual or five-year cycle, and peer review is not triggered by the type of report issued.
Under AU-C 200, which description matches professional skepticism?
- a.An attitude that includes a questioning mind and a critical assessment of audit evidence✓
- b.Applying relevant training and experience to make informed decisions in the audit
- c.A requirement to test every transaction whenever fraud is suspected in an account
- d.A presumption that management is dishonest until the evidence proves otherwise
AU-C 200.14 defines professional skepticism as an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to fraud or error, and a critical assessment of audit evidence. Applying training, knowledge, and experience to make informed decisions is the definition of professional judgment, a related but separate concept. Skepticism does not assume management is dishonest, and no standard requires testing every transaction because fraud is suspected.
An audit senior accepts an inventory aging report generated by a nonissuer's ERP system without question, even though warehouse staff told her that many items shown as current have not moved in over a year. Which unconscious auditor bias described in AU-C 220 does this behavior most directly illustrate?
- a.Groupthink
- b.Anchoring bias
- c.Availability bias
- d.Automation bias✓
AU-C 220.A37 describes automation bias as a tendency to favor output from automated systems even when human reasoning or contradictory information raises questions about whether the output is reliable. Here the warehouse staff's comments contradicted the system report and were ignored. Availability bias gives more weight to events that come readily to mind, groupthink is a tendency to decide as a group and discourage individual responsibility, and anchoring bias relies too heavily on an initial piece of information.
Which statement correctly compares engagements performed under the SSARSs for a nonissuer?
- a.A compilation gives limited assurance and requires independence; a review gives reasonable assurance
- b.A review gives reasonable assurance, obtained mainly through inquiry and analytical procedures
- c.A review gives limited assurance and requires independence; a compilation gives no assurance✓
- d.A preparation engagement gives limited assurance and must be followed by a compilation report
AR-C 90.10 requires the accountant to be independent when performing a review, and a review obtains limited assurance, primarily through analytical procedures and inquiry. AR-C 80.02 states that a compilation is not an assurance engagement. A preparation engagement under AR-C 70 provides no assurance, and no report is required when each page carries a no-assurance statement. None of these engagements gives reasonable assurance, which only an audit or examination provides.
Management of a prospective nonissuer audit client refuses to acknowledge its responsibility for designing, implementing, and maintaining internal control relevant to the financial statements. No law or regulation requires the auditor to accept. Under AU-C 210, the auditor should
- a.accept, and plan to express a qualified opinion
- b.not accept the proposed audit engagement✓
- c.accept, but assess control risk at the maximum
- d.accept, and describe the refusal in an other-matter paragraph
Obtaining management's acknowledgment of its responsibility for internal control is one of the preconditions for an audit in AU-C 210.06. Paragraph .08 says that if this agreement is not obtained, the auditor should not accept the engagement unless required by law or regulation. Planning a qualified opinion, assessing control risk at the maximum, or adding report language would all mean accepting an engagement whose preconditions are missing.
Midway through an audit of a nonissuer, the auditor cannot obtain sufficient appropriate audit evidence about receivables. Management asks to change the engagement to a review so the report will not be qualified. Under AU-C 210, how should the auditor view this request?
- a.As acceptable, if the review report mentions the original audit engagement
- b.As lacking reasonable justification for the change✓
- c.As acceptable, as long as management puts the request in writing
- d.As acceptable, because management may choose a lower level of service
AU-C 210.A42 gives this exact situation as an example of a change that may not be considered reasonable: the request relates to unsatisfactory information and is made to avoid a qualified opinion or disclaimer. Management cannot simply choose a lower level of service; paragraph .17 bars agreeing to a change without reasonable justification. Even when a change is justified, AU-C 210.A44 says the new report should not refer to the original audit, and a written request does not supply a justification.
Before accepting an initial audit of a nonissuer, the successor auditor asks management to authorize the predecessor auditor to respond fully to inquiries. Management refuses. Under AU-C 210, the successor auditor should
- a.decline the engagement, since a refusal automatically rules out acceptance
- b.accept now and review the predecessor's workpapers after the engagement letter is signed
- c.contact the predecessor anyway, since the AICPA Code requires members to cooperate
- d.inquire about the reasons and consider the implications in deciding whether to accept✓
AU-C 210.11 requires the successor to ask management to authorize the predecessor to respond. If management refuses or limits the response, the successor should ask about the reasons and consider the implications in deciding whether to accept. The predecessor's duty to respond under paragraph .13 applies only when management authorizes it, so contacting the predecessor without authorization is not the answer. The standard does not make refusal an automatic bar, and the inquiry is required before acceptance, not after.
Want these explained in order? CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
For an audit of a nonissuer, within which limits does AU-C 230 require the auditor to assemble the final audit file and to retain the audit documentation?
- a.Assemble within 60 days of the report release date; retain at least 5 years from that date✓
- b.Assemble within 45 days after the report date; retain at least 7 years from that date
- c.Assemble within 90 days after the balance sheet date; retain at least 5 years from that date
- d.Assemble within 30 days after the report release date; retain at least 3 years from that date
AU-C 230.16 requires assembly of the final audit file no later than 60 days after the report release date, and paragraph .17 sets a retention period of not less than five years from the report release date. PCAOB AS 1215 sets different limits for issuer audits, including seven-year retention, but it does not govern this engagement. Thirty days, three years, and the balance sheet date do not appear in AU-C 230.
In an audit of a nonissuer, the auditor identified two significant deficiencies in internal control, one of which management fixed before year-end. Under AU-C 265, how and when must they be communicated to those charged with governance?
- a.Both, in writing, no later than 60 days after the report release date✓
- b.Both, orally, at any time before next year's audit begins
- c.Only the uncorrected one, in writing, before the report is released
- d.Only the uncorrected one, in writing, within 30 days after the fiscal year-end
AU-C 265.11 requires written communication of significant deficiencies and material weaknesses identified during the audit, including those that were remediated during the audit. Paragraph .13 requires the communication no later than 60 days after the report release date, and .A17 notes it is best made by the release date. Oral communication does not meet the requirement, and there is no rule based on 30 days after year-end.
Under PCAOB AS 1305, by when must the auditor of an issuer communicate in writing to management and the audit committee all significant deficiencies and material weaknesses identified in an audit of the financial statements?
- a.Before the auditor's report is issued✓
- b.Within 45 days after the report release date
- c.Only at the next audit committee meeting after year-end
- d.No later than 60 days after the report release date
AS 1305.04 requires written communication of all significant deficiencies and material weaknesses to management and the audit committee, and states that it should be made before the auditor's report on the financial statements is issued. The 60-day window comes from AU-C 265, which governs nonissuer audits. The other timings do not appear in AS 1305.
A U.S. CPA firm applies SQMS No. 2. The engagement partner on last year's audit of a nonissuer is proposed as this year's engagement quality reviewer on the same audit. What does SQMS No. 2 require?
- a.No consideration at all, because the reviewer role is separate from prior service
- b.A permanent ban on a former engagement partner ever reviewing that engagement
- c.Its policies must address the objectivity threat; no fixed cooling-off period applies✓
- d.A mandatory two-year cooling-off period before the former engagement partner may serve as reviewer
QM section 20.19 requires the firm's policies to address threats to objectivity when someone becomes engagement quality reviewer after serving as the engagement partner. Paragraph .A16 says a firm may set a cooling-off period, and the ASB's comparison with ISQM 2 explains that the U.S. standard deliberately omits ISQM 2's mandatory two-year cooling-off. No permanent ban exists, but the threat cannot be ignored either.
In planning an audit of a nonissuer, which item belongs in the audit plan rather than in the overall audit strategy?
- a.The reporting objectives, used to plan the timing of required communications
- b.Planned further audit procedures at the relevant assertion level✓
- c.The nature, timing, and extent of the resources needed for the engagement
- d.The characteristics of the engagement that define its scope
AU-C 300.08 places the scope of the engagement, the reporting objectives, the factors that direct the team's efforts, and the resources needed in the overall audit strategy. AU-C 300.09 lists the contents of the audit plan: planned direction, supervision, and review; planned risk assessment procedures; and the nature, timing, and extent of planned further audit procedures at the relevant assertion level. The strategy sets the broad approach and the plan turns it into specific procedures.
Under Section 301 of the Sarbanes-Oxley Act, who is directly responsible for the appointment, compensation, and oversight of the work of an issuer's registered public accounting firm?
- a.The audit committee✓
- b.The chief financial officer
- c.The PCAOB, on the issuer's behalf
- d.The shareholders at the annual meeting
SOX Section 301 (Exchange Act Section 10A(m)(2)) makes the audit committee, as a committee of the board, directly responsible for appointing, compensating, and overseeing the registered public accounting firm, including resolving disagreements between management and the auditor. The firm reports directly to the audit committee. Management, including the CFO, does not hold that authority. Shareholders may ratify the choice in practice, but the statute assigns the responsibility to the committee. The PCAOB oversees audit firms; it does not engage auditors for issuers.
Under Section 302 of the Sarbanes-Oxley Act, the principal executive and financial officers of an issuer certify each annual and quarterly report. Which statement is part of that certification?
- a.The issuer has adopted a code of ethics that applies to all of its employees
- b.No fraud of any size occurred at the issuer during the period covered by the report
- c.The signing officers are responsible for establishing and maintaining internal controls✓
- d.The external auditor has attested to management's internal control assessment
Section 302(a)(4) requires the signing officers to certify that they are responsible for establishing and maintaining internal controls, have designed them so that material information reaches them, and have evaluated their effectiveness. Auditor attestation comes from Section 404(b), not from the officers' certification. Section 406 requires disclosure of whether a code of ethics exists for senior financial officers, not all employees. The officers disclose fraud involving management or key control employees to the auditors and audit committee; they do not certify that no fraud of any size occurred.
Which requirement comes from Section 407 of the Sarbanes-Oxley Act?
- a.Certification of each periodic report by the CEO and the CFO
- b.Disclosure of whether the audit committee has a financial expert✓
- c.Auditor attestation to management's internal control assessment
- d.A rule that every member of the audit committee must be a licensed CPA
Section 407 directs the SEC to require each issuer to disclose whether its audit committee includes at least one member who is a financial expert and, if not, why not. It does not require committee members to be CPAs. Auditor attestation on internal control comes from Section 404(b), and officer certification of periodic reports comes from Section 302.
For purposes of GAAS, an entity's system of internal control consists of five interrelated components. Which list names them?
- a.Control environment, risk assessment process, monitoring process, information and communication, control activities✓
- b.Governance, fraud risk assessment, information system, physical controls, external audit
- c.Tone at the top, risk assessment process, authorization, reconciliations, monitoring process
- d.Control environment, segregation of duties, IT general controls, internal audit, control activities
AU-C 315.12 defines the system of internal control as having five components: the control environment, the entity's risk assessment process, the entity's process to monitor the system of internal control, the information system and communication, and control activities. These match the five COSO components. Segregation of duties, authorizations, reconciliations, and IT general controls are types of control activities, not separate components. Internal audit is part of monitoring, and the external auditor is not part of the entity's system at all.
A purchasing clerk and a receiving supervisor agree to record receipts of goods that were never delivered, so the automated three-way match reports no exceptions. This situation best illustrates which inherent limitation of internal control?
- a.A reviewer who misunderstands the purpose of an exception report
- b.Management's decision to accept a known risk as a cost matter
- c.Faulty human judgment in how the control was designed
- d.Circumvention of controls by collusion of two or more people✓
AU-C 315 appendix C (par. 24) notes that controls can be circumvented by the collusion of two or more people or by inappropriate management override. Here two employees acting together defeated a control that was properly designed. Faulty judgment in design and a reviewer who does not understand an exception report are other limitations listed in paragraph 23, but they do not describe this case. Management's choice to accept a risk is discussed in paragraph 25 and is not what happened here.
Which of the following is a general IT control rather than an information-processing control?
- a.A three-way match of purchase order, receiving report, and invoice
- b.An automated edit check rejecting sales orders over credit limits
- c.Periodic review of user access rights to the ERP system✓
- d.System calculation of monthly depreciation for each fixed asset
AU-C 315.12 defines general IT controls as controls over the entity's IT processes that support the continued proper operation of the IT environment, and it names those processes as managing access, managing program changes, and managing IT operations. A review of user access rights is an access control. Edit checks, three-way matches, and automated calculations act directly on individual transactions and are information-processing controls.
A SOC 1 type 2 report for a payroll processor lists complementary user entity controls, including the user entity's review of payroll change reports. What should the auditor of the user entity, a nonissuer, do about these controls?
- a.If they address relevant risks, understand whether the entity designed and implemented them✓
- b.Ignore them, since complementary user entity controls are the service organization's duty
- c.Ask the service auditor to test these controls at the user entity during its next examination
- d.Rely on the service auditor's opinion, which already covers the user entity's controls
AU-C 402.14c requires the user auditor to determine whether complementary user entity controls address risks of material misstatement in relevant assertions and, if so, to understand whether the user entity has designed and implemented them. By definition these are controls the service organization assumes the user entity will put in place, so the service auditor's opinion does not cover them. The service auditor does not test controls at user entities.
The auditor of a nonissuer used a SOC 1 type 2 report as audit evidence and is issuing an unmodified opinion. Under AU-C 402, may the auditor's report refer to the service auditor's work?
- a.Yes, in order to divide responsibility between the two auditors
- b.Yes, reference is required whenever such a report is used as evidence
- c.Yes, provided the service auditor's name and report date are stated
- d.No, the report should not refer to the service auditor's work✓
AU-C 402.21 states that the user auditor should not refer to the work of a service auditor in a report containing an unmodified opinion. Paragraph .22 allows a reference only when it helps explain a modified opinion, and even then the report must say the reference does not reduce the user auditor's responsibility. The user auditor never divides responsibility with a service auditor.
In an audit of a nonissuer, no specific risks of material misstatement due to fraud have been identified. Which procedure does AU-C 240 still require in order to address the risk of management override of controls?
- a.Confirming every related party balance with the counterparty
- b.Testing the appropriateness of journal entries and other adjustments✓
- c.Obtaining a separate representation letter from the board
- d.Observing a surprise count of all petty cash funds
AU-C 240.32 requires, apart from any specific fraud risks, procedures to test journal entries and other adjustments, to review accounting estimates for bias (including a retrospective review), and to evaluate the business rationale of significant unusual transactions. Confirming related party balances and counting petty cash may be useful in some audits but are not required responses to override. A separate board representation letter is not required by AU-C 240.
A nonissuer's sales managers receive bonuses only if quarterly revenue beats budget, and the budget was raised 30% this year even though the market is flat. Using the fraud risk factor categories in AU-C 240, these facts primarily indicate
- a.an attitude or rationalization for fraud
- b.an incentive or pressure to commit fraud✓
- c.an actual fraud that must be reported to regulators
- d.an opportunity to misappropriate assets
AU-C 240.11 and its appendix A group fraud risk factors by incentive or pressure, perceived opportunity, and attitude or rationalization. Compensation that depends on hitting aggressive revenue targets is an incentive or pressure to overstate revenue. Nothing in the facts shows a weakness that creates an opportunity, or an attitude that justifies misconduct. Risk factors are conditions, not evidence that fraud has occurred.
At a small nonissuer, one employee opens the mail, deposits customer checks, posts cash receipts to customer accounts, and reconciles the bank account. Using the fraud risk factor categories in AU-C 240, this primarily indicates
- a.a significant unusual transaction
- b.an opportunity to misappropriate assets✓
- c.an incentive or pressure to misstate revenue
- d.an attitude or rationalization for fraud
Fraud risk factors in AU-C 240 fall into incentive or pressure, perceived opportunity, and attitude or rationalization. Letting one person both handle cash and keep the related records, with no independent reconciliation, is inadequate segregation of duties, which creates an opportunity to steal and conceal it. The facts say nothing about pressure or attitude, and routine cash receipts are not significant unusual transactions.
In an audit of a nonissuer, the auditor concludes that the presumed risk of fraud in revenue recognition does not apply, because the entity earns only fixed monthly rent under a few long-term leases. Under AU-C 240, what must the auditor do?
- a.Document the reasons for that conclusion✓
- b.Still treat revenue as a significant fraud risk
- c.Disclose the rebuttal in the auditor's report
- d.Obtain approval from those charged with governance
AU-C 240.26 establishes a presumption that fraud risks exist in revenue recognition, and paragraph .A35 recognizes that the presumption may be rebutted. When it is, paragraph .46 requires the auditor to document the reasons for that conclusion. Governance approval is not required, the auditor does not have to keep treating revenue as a fraud risk once the presumption is overcome, and the conclusion is not reported in the auditor's report.
The auditor of a nonissuer uses 5% of pretax income from continuing operations as a starting point for materiality for the financial statements as a whole. Pretax income is $1,800,000, including a $600,000 one-time gain that the auditor decides to exclude as exceptional. What is the starting-point materiality?
- a.$30,000
- b.$60,000✓
- c.$120,000
- d.$90,000
AU-C 320.A8 notes that when an exceptional item distorts profit before tax, the auditor may conclude that materiality is better based on a normalized profit figure. Normalized pretax income is $1,800,000 - $600,000 = $1,200,000, and 5% of that is $60,000. Using the unadjusted $1,800,000 gives $90,000, applying 5% to the gain alone gives $30,000, and adding the gain instead of removing it ($2,400,000) gives $120,000. The percentage is the auditor's judgment; GAAS does not prescribe one.
Why does an auditor set performance materiality at an amount less than materiality for the financial statements as a whole?
- a.To limit the risk that uncorrected plus undetected misstatements exceed materiality✓
- b.To fix the level at which management may decline to record proposed adjustments
- c.To set the amount below which misstatements are clearly trivial and need not be accumulated
- d.To set the threshold above which a misstatement must be described in the auditor's report
AU-C 320.09 defines performance materiality as the amount set below overall materiality to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds materiality for the financial statements as a whole. The clearly trivial threshold is a separate, much smaller amount under AU-C 450. Misstatements are not described in the report based on performance materiality, and management does not get a threshold for refusing corrections.
During fieldwork on a nonissuer audit, actual revenue proves to be 20% below the forecast used to set materiality, and the auditor lowers materiality for the financial statements as a whole. Under AU-C 320, what else should the auditor do?
- a.Reconsider performance materiality and the planned procedures✓
- b.Keep performance materiality unchanged, since it was set during planning
- c.Document the change only if materiality fell by more than half
- d.Raise the clearly trivial threshold to offset the lower materiality
AU-C 320.12 requires the auditor to revise materiality when information arises that would have led to a different amount initially. Paragraph .13 then requires the auditor to determine whether performance materiality needs revising and whether the nature, timing, and extent of further audit procedures remain appropriate. Freezing performance materiality ignores that requirement, raising the trivial threshold works in the wrong direction, and the standard sets no 50% trigger for documentation.
Showing 40 of 111