24 questions

Ethics, Professional Responsibilities and General Principles

Maria, a staff auditor on the engagement team for the audit of Crane Co., a nonissuer, inherits Crane shares worth $900, an amount immaterial to her. She obtains the right to sell the shares on March 3. Under the AICPA Code of Professional Conduct, what must happen for her independence not to be impaired?

  • a.She tells the engagement partner about the shares and keeps them, since they are immaterial
  • b.She transfers the shares to her spouse before the auditor's report is issued
  • c.She keeps the shares until the auditor's report is released and then sells them
  • d.She disposes of the shares within 30 days after she obtains the right to dispose of them✓

The Unsolicited Financial Interests interpretation (ET 1.240.020) accepts an inherited interest only if the covered member disposes of it as soon as practicable and no later than 30 days after gaining knowledge of it and the right to dispose of it. Materiality does not matter for a direct financial interest: ET 1.240.010 says any direct interest held during the period of the professional engagement impairs independence, so telling the partner does not cure it. A spouse is immediate family, whose interests are treated as the covered member's own, and holding the shares until the report is released keeps a direct interest during the engagement period.

Ethics, Professional Responsibilities and General Principles

A CPA firm is about to issue its current-year audit report for a nonissuer client. The client still owes the firm a fee, significant to the firm, for tax services the firm performed 14 months before the report date. Under the AICPA Code, which conclusion follows?

  • a.Independence is impaired unless the fee is paid before the report is issued✓
  • b.Independence is not impaired if the client signs a promissory note for the unpaid fee
  • c.Independence is impaired only if the unpaid fee is for prior audit services
  • d.Independence is not impaired if the unpaid fee is disclosed in the report

ET 1.230.010.03 says threats are not at an acceptable level if, when the current-year attest report is issued, unpaid fees are significant to the covered member and relate to services provided more than one year before the report date. The interpretation covers fees for any professional services, not only audit fees. It also states that unpaid fees include a note receivable arising from such fees, so signing a note changes nothing, and there is no provision for curing the threat by disclosure in the report.

Ethics, Professional Responsibilities and General Principles

The owner of a nonissuer audit client asks the audit firm to design the company's new payroll approval process. The owner says no one at the company has the time or knowledge to oversee the work and asks the firm to decide on the final design. Under the AICPA Code, what is the effect on independence?

  • a.Not impaired, provided that a partner who is not on the audit team does the work
  • b.Impaired, since management cannot oversee the work or take responsibility for it✓
  • c.Not impaired, as long as the firm documents the work in an engagement letter
  • d.Impaired only if payroll expense is material to the financial statements as a whole

The general requirements for nonattest services (ET 1.295.040) require management to designate an individual with suitable skill, knowledge, or experience to oversee the service and to accept responsibility for its results. If the client cannot or will not do so, the member's performance of the service impairs independence. A written understanding is a separate required safeguard, not a substitute for management's responsibility, and having a different partner do the work does not change who makes the decisions. The rule contains no materiality exception.

Ethics, Professional Responsibilities and General Principles

Management of a nonissuer attest client sues its audit firm, alleging deficient audit work in the prior year. Under the AICPA Conceptual Framework for Independence, the lawsuit creates which type of threat?

  • a.Management participation threat
  • b.Familiarity threat
  • c.Undue influence threat
  • d.Adverse interest threat✓

ET 1.210.010.12 describes an adverse interest threat as one where the member's interests are opposed to the attest client's, and gives the client or member starting litigation against the other as its example. A familiarity threat comes from a long or close relationship. A management participation threat comes from taking on management's role. An undue influence threat arises when the member gives in to pressure or dominance, such as a threat to replace the firm.

Ethics, Professional Responsibilities and General Principles

A CPA in public practice wants to upload a client's general ledger to a cloud-based AI analytics tool operated by an outside vendor. Under the AICPA Code of Professional Conduct, what must the CPA do before disclosing the client's confidential information to the vendor?

  • a.Tell the client after the engagement is finished that an outside vendor was used
  • b.Obtain written approval from the state board of accountancy before uploading any data
  • c.Get the client's consent, or bind the vendor by contract and verify its safeguards✓
  • d.Nothing further, because a vendor assisting the CPA is treated as part of the CPA's firm

The interpretation on disclosing information to a third-party service provider (ET 1.700.040) requires one of two things before disclosure: specific consent from the client, or a contract requiring the provider to keep the information confidential together with reasonable assurance that the provider has procedures to prevent unauthorized release. A vendor is not treated as part of the firm. No state board approval is involved, and telling the client after the fact does not meet the requirement, which applies before disclosure.

Ethics, Professional Responsibilities and General Principles

A CPA firm audits the financial statements of Brook LLC, a nonissuer. Which fee arrangement for another service to Brook is permitted under the AICPA Code?

  • a.A fee equal to 25% of the refund obtained through an amended tax return
  • b.A consulting fee payable only if Brook's new bank loan is approved
  • c.A consulting fee that varies with the complexity of the work performed✓
  • d.A bonus payable only if Brook's sales rise 10% after a pricing study

The Contingent Fees Rule (ET 1.510.001) bars a member from performing any service for a contingent fee for a client whose financial statements the firm audits, and bars contingent fees for preparing an original or amended return or refund claim for any client. A fee paid only if the loan is approved, or only if sales reach a target, depends on a finding or result and is contingent. The rule states that fees may vary with the complexity of the services rendered, so that arrangement is permitted.

Ethics, Professional Responsibilities and General Principles

Lena, a CPA in public practice, compiles financial statements for Oak Corp. that she expects Oak's bank to use. Her compilation report discloses her lack of independence, and she performs no other attest services for Oak. A software vendor will pay her a commission if Oak buys its product on her recommendation. Under the AICPA Code, which statement is true?

  • a.She may accept the commission only with the bank's written consent
  • b.She may accept the commission with no disclosure, as she is not independent
  • c.She may accept the commission but must disclose it to Oak✓
  • d.She may not accept any commission, because Oak is her compilation client

The Commissions and Referral Fees Rule (ET 1.520.001.01) bars commissions from a client for whom the member performs an audit, a review, a compilation that a third party is expected to use when the report does not disclose a lack of independence, or an examination of prospective financial information. Lena's report discloses her lack of independence, so the prohibition does not apply. Paragraph .03 then requires her to disclose the permitted commission to the person to whom she recommends the product. The bank's consent plays no part in the rule.

Ethics, Professional Responsibilities and General Principles

Under the SEC's auditor independence rules (Regulation S-X Rule 2-01), a lead audit partner has served in that role on an issuer's audit for five consecutive years. When may that partner next serve as lead partner or engagement quality reviewer for this issuer?

  • a.After a two-year time-out period
  • b.Immediately, if the audit committee approves
  • c.After a one-year time-out period
  • d.After a five-year time-out period✓

Rule 2-01(c)(6)(i)(A)(1) limits the lead partner and the engagement quality reviewer to five consecutive years, and (c)(6)(i)(B)(1) bars the partner from either role for the five consecutive years that follow. A two-year time-out applies to other audit partners after seven years. One year is the employment cooling-off period in Rule 2-01(c)(2)(iii)(B), not a rotation period. Audit committee approval is not an exception; the only relief is for small firms whose engagements the PCAOB reviews every three years.

Ethics, Professional Responsibilities and General Principles

Jin worked about 300 hours as audit senior on the audit of Vega Corp., an issuer, during the year before audit procedures began for the fiscal period in which Vega hired him as its CFO. Under SEC Rule 2-01, what is the effect on the audit firm?

  • a.The firm remains independent if Jin worked fewer than 500 hours on the audit
  • b.The firm remains independent if Jin has no capital balance in the firm
  • c.The firm is not independent of Vega✓
  • d.The firm remains independent if a partner replaces Jin on the audit team

Rule 2-01(c)(2)(iii)(B) says a firm is not independent when a former engagement team member takes a financial reporting oversight role at an issuer unless that person was not on the audit engagement team during the one-year period before audit procedures began for the period that includes the hire date. Settling capital balances and financial arrangements is a separate condition in (c)(2)(iii)(A) and does not satisfy the cooling-off test. The only hours exception excludes people other than the lead partner and engagement quality reviewer who provided 10 or fewer hours, so 300 hours does not qualify. Staffing changes do not cure the problem.

Ethics, Professional Responsibilities and General Principles

An accounting firm audits Delta Inc., an issuer. Assuming the audit committee pre-approves it, which service could the firm provide to Delta without impairing independence under SEC Rule 2-01?

  • a.Performing Delta's outsourced internal audit of financial controls
  • b.Designing the software that generates Delta's sales ledger
  • c.Valuing an acquired brand that Delta will record as an asset
  • d.Preparing Delta's federal corporate income tax return✓

Rule 2-01(c)(4) lists the prohibited non-audit services. They include financial information systems design and implementation, internal audit outsourcing related to internal accounting controls, and appraisal or valuation services whose results will be subject to audit. Tax compliance work is not on that list. It is allowed when the audit committee pre-approves it under Rule 2-01(c)(7), subject to the PCAOB's separate tax-service rules.

Want these explained in order? CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Ethics, Professional Responsibilities and General Principles

Under SEC Rule 2-01(c)(7), the audit committee's pre-approval requirement for a non-audit service by an issuer's auditor may be waived only if, among other conditions, all such services add up to no more than what share of the total fees paid by the client to its auditor for the fiscal year?

  • a.1 percent
  • b.15 percent
  • c.10 percent
  • d.5 percent✓

Rule 2-01(c)(7)(i)(C) allows the de minimis exception only when the aggregate amount of such services is no more than five percent of total revenues the audit client paid to its accountant during the fiscal year. The services also must not have been recognized as non-audit services when the engagement began, and they must be brought to the audit committee promptly and approved before the audit is completed. The other percentages do not appear in the rule.

Ethics, Professional Responsibilities and General Principles

Under the Department of Labor's interpretive bulletin on the independence of accountants who audit employee benefit plans, which circumstance would make the accountant not independent for the plan's audit?

  • a.A member of the accounting firm maintains the plan's financial records✓
  • b.A former sponsor employee now at the firm has fully cut ties and is off the plan audit
  • c.An actuary associated with the firm provides actuarial services to the plan
  • d.The firm is separately engaged by the plan sponsor for other professional work

The DOL bulletin (29 CFR 2509.2022-01, which the AICPA blueprint cites under its former number 2509.75-9) states in paragraph (b)(3) that an accountant is not independent if the accountant or a member of the firm maintains financial records for the plan. Paragraph (c)(1) says an accountant does not lose independence solely because the firm is engaged by the plan sponsor or because an associated actuary serves the plan. Paragraph (b)(2) exempts a former employee of the plan or sponsor who has completely disassociated and does not audit periods of his or her employment.

Ethics, Professional Responsibilities and General Principles

Under the 2024 revision of Government Auditing Standards, how much continuing professional education must an auditor who performs engagement procedures on a GAGAS engagement complete?

  • a.40 hours every year, 12 of them in government auditing, with no carryover allowed
  • b.120 hours every 3 years, with no government-related minimum and 20 hours in each year
  • c.80 hours every 2 years, 24 of them government-related, and at least 20 hours in each year✓
  • d.80 hours every 2 years, 56 of them government-related, and at least 10 hours in each year

Paragraph 4.16 of the 2024 Yellow Book requires at least 80 hours of CPE in every 2-year period: 24 hours on the government environment, government auditing, or the audited entity's specific environment, and 56 hours that enhance professional expertise. Paragraph 4.17 adds a minimum of 20 hours in each year of the 2-year period. The 120-hour and 40-hour patterns are not GAGAS rules, and the 56 hours are the general portion, not the government-specific one.

Ethics, Professional Responsibilities and General Principles

An audit organization that performs GAGAS engagements is not already subject to a peer review requirement. How often does the 2024 revision of Government Auditing Standards require it to obtain an external peer review?

  • a.Only after issuing a modified report
  • b.At least once every 3 years✓
  • c.At least once every year
  • d.At least once every 5 years

Paragraph 5.179 of the 2024 Yellow Book states that an audit organization not already subject to a peer review requirement should obtain an external peer review at least once every 3 years. The standard does not set an annual or five-year cycle, and peer review is not triggered by the type of report issued.

Ethics, Professional Responsibilities and General Principles

Under AU-C 200, which description matches professional skepticism?

  • a.An attitude that includes a questioning mind and a critical assessment of audit evidence✓
  • b.Applying relevant training and experience to make informed decisions in the audit
  • c.A requirement to test every transaction whenever fraud is suspected in an account
  • d.A presumption that management is dishonest until the evidence proves otherwise

AU-C 200.14 defines professional skepticism as an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to fraud or error, and a critical assessment of audit evidence. Applying training, knowledge, and experience to make informed decisions is the definition of professional judgment, a related but separate concept. Skepticism does not assume management is dishonest, and no standard requires testing every transaction because fraud is suspected.

Ethics, Professional Responsibilities and General Principles

An audit senior accepts an inventory aging report generated by a nonissuer's ERP system without question, even though warehouse staff told her that many items shown as current have not moved in over a year. Which unconscious auditor bias described in AU-C 220 does this behavior most directly illustrate?

  • a.Groupthink
  • b.Anchoring bias
  • c.Availability bias
  • d.Automation bias✓

AU-C 220.A37 describes automation bias as a tendency to favor output from automated systems even when human reasoning or contradictory information raises questions about whether the output is reliable. Here the warehouse staff's comments contradicted the system report and were ignored. Availability bias gives more weight to events that come readily to mind, groupthink is a tendency to decide as a group and discourage individual responsibility, and anchoring bias relies too heavily on an initial piece of information.

Ethics, Professional Responsibilities and General Principles

Which statement correctly compares engagements performed under the SSARSs for a nonissuer?

  • a.A compilation gives limited assurance and requires independence; a review gives reasonable assurance
  • b.A review gives reasonable assurance, obtained mainly through inquiry and analytical procedures
  • c.A review gives limited assurance and requires independence; a compilation gives no assurance✓
  • d.A preparation engagement gives limited assurance and must be followed by a compilation report

AR-C 90.10 requires the accountant to be independent when performing a review, and a review obtains limited assurance, primarily through analytical procedures and inquiry. AR-C 80.02 states that a compilation is not an assurance engagement. A preparation engagement under AR-C 70 provides no assurance, and no report is required when each page carries a no-assurance statement. None of these engagements gives reasonable assurance, which only an audit or examination provides.

Ethics, Professional Responsibilities and General Principles

Management of a prospective nonissuer audit client refuses to acknowledge its responsibility for designing, implementing, and maintaining internal control relevant to the financial statements. No law or regulation requires the auditor to accept. Under AU-C 210, the auditor should

  • a.accept, and plan to express a qualified opinion
  • b.not accept the proposed audit engagement✓
  • c.accept, but assess control risk at the maximum
  • d.accept, and describe the refusal in an other-matter paragraph

Obtaining management's acknowledgment of its responsibility for internal control is one of the preconditions for an audit in AU-C 210.06. Paragraph .08 says that if this agreement is not obtained, the auditor should not accept the engagement unless required by law or regulation. Planning a qualified opinion, assessing control risk at the maximum, or adding report language would all mean accepting an engagement whose preconditions are missing.

Ethics, Professional Responsibilities and General Principles

Midway through an audit of a nonissuer, the auditor cannot obtain sufficient appropriate audit evidence about receivables. Management asks to change the engagement to a review so the report will not be qualified. Under AU-C 210, how should the auditor view this request?

  • a.As acceptable, if the review report mentions the original audit engagement
  • b.As lacking reasonable justification for the change✓
  • c.As acceptable, as long as management puts the request in writing
  • d.As acceptable, because management may choose a lower level of service

AU-C 210.A42 gives this exact situation as an example of a change that may not be considered reasonable: the request relates to unsatisfactory information and is made to avoid a qualified opinion or disclaimer. Management cannot simply choose a lower level of service; paragraph .17 bars agreeing to a change without reasonable justification. Even when a change is justified, AU-C 210.A44 says the new report should not refer to the original audit, and a written request does not supply a justification.

Ethics, Professional Responsibilities and General Principles

Before accepting an initial audit of a nonissuer, the successor auditor asks management to authorize the predecessor auditor to respond fully to inquiries. Management refuses. Under AU-C 210, the successor auditor should

  • a.decline the engagement, since a refusal automatically rules out acceptance
  • b.accept now and review the predecessor's workpapers after the engagement letter is signed
  • c.contact the predecessor anyway, since the AICPA Code requires members to cooperate
  • d.inquire about the reasons and consider the implications in deciding whether to accept✓

AU-C 210.11 requires the successor to ask management to authorize the predecessor to respond. If management refuses or limits the response, the successor should ask about the reasons and consider the implications in deciding whether to accept. The predecessor's duty to respond under paragraph .13 applies only when management authorizes it, so contacting the predecessor without authorization is not the answer. The standard does not make refusal an automatic bar, and the inquiry is required before acceptance, not after.

Want these explained in order? CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Ethics, Professional Responsibilities and General Principles

For an audit of a nonissuer, within which limits does AU-C 230 require the auditor to assemble the final audit file and to retain the audit documentation?

  • a.Assemble within 60 days of the report release date; retain at least 5 years from that date✓
  • b.Assemble within 45 days after the report date; retain at least 7 years from that date
  • c.Assemble within 90 days after the balance sheet date; retain at least 5 years from that date
  • d.Assemble within 30 days after the report release date; retain at least 3 years from that date

AU-C 230.16 requires assembly of the final audit file no later than 60 days after the report release date, and paragraph .17 sets a retention period of not less than five years from the report release date. PCAOB AS 1215 sets different limits for issuer audits, including seven-year retention, but it does not govern this engagement. Thirty days, three years, and the balance sheet date do not appear in AU-C 230.

Ethics, Professional Responsibilities and General Principles

In an audit of a nonissuer, the auditor identified two significant deficiencies in internal control, one of which management fixed before year-end. Under AU-C 265, how and when must they be communicated to those charged with governance?

  • a.Both, in writing, no later than 60 days after the report release date✓
  • b.Both, orally, at any time before next year's audit begins
  • c.Only the uncorrected one, in writing, before the report is released
  • d.Only the uncorrected one, in writing, within 30 days after the fiscal year-end

AU-C 265.11 requires written communication of significant deficiencies and material weaknesses identified during the audit, including those that were remediated during the audit. Paragraph .13 requires the communication no later than 60 days after the report release date, and .A17 notes it is best made by the release date. Oral communication does not meet the requirement, and there is no rule based on 30 days after year-end.

Ethics, Professional Responsibilities and General Principles

Under PCAOB AS 1305, by when must the auditor of an issuer communicate in writing to management and the audit committee all significant deficiencies and material weaknesses identified in an audit of the financial statements?

  • a.Before the auditor's report is issued✓
  • b.Within 45 days after the report release date
  • c.Only at the next audit committee meeting after year-end
  • d.No later than 60 days after the report release date

AS 1305.04 requires written communication of all significant deficiencies and material weaknesses to management and the audit committee, and states that it should be made before the auditor's report on the financial statements is issued. The 60-day window comes from AU-C 265, which governs nonissuer audits. The other timings do not appear in AS 1305.

Ethics, Professional Responsibilities and General Principles

A U.S. CPA firm applies SQMS No. 2. The engagement partner on last year's audit of a nonissuer is proposed as this year's engagement quality reviewer on the same audit. What does SQMS No. 2 require?

  • a.No consideration at all, because the reviewer role is separate from prior service
  • b.A permanent ban on a former engagement partner ever reviewing that engagement
  • c.Its policies must address the objectivity threat; no fixed cooling-off period applies✓
  • d.A mandatory two-year cooling-off period before the former engagement partner may serve as reviewer

QM section 20.19 requires the firm's policies to address threats to objectivity when someone becomes engagement quality reviewer after serving as the engagement partner. Paragraph .A16 says a firm may set a cooling-off period, and the ASB's comparison with ISQM 2 explains that the U.S. standard deliberately omits ISQM 2's mandatory two-year cooling-off. No permanent ban exists, but the threat cannot be ignored either.

Report