33 questions

Assessing Risk and Developing a Planned Response

In planning an audit of a nonissuer, which item belongs in the audit plan rather than in the overall audit strategy?

  • a.The reporting objectives, used to plan the timing of required communications
  • b.Planned further audit procedures at the relevant assertion level✓
  • c.The nature, timing, and extent of the resources needed for the engagement
  • d.The characteristics of the engagement that define its scope

AU-C 300.08 places the scope of the engagement, the reporting objectives, the factors that direct the team's efforts, and the resources needed in the overall audit strategy. AU-C 300.09 lists the contents of the audit plan: planned direction, supervision, and review; planned risk assessment procedures; and the nature, timing, and extent of planned further audit procedures at the relevant assertion level. The strategy sets the broad approach and the plan turns it into specific procedures.

Assessing Risk and Developing a Planned Response

Under Section 301 of the Sarbanes-Oxley Act, who is directly responsible for the appointment, compensation, and oversight of the work of an issuer's registered public accounting firm?

  • a.The audit committee✓
  • b.The chief financial officer
  • c.The PCAOB, on the issuer's behalf
  • d.The shareholders at the annual meeting

SOX Section 301 (Exchange Act Section 10A(m)(2)) makes the audit committee, as a committee of the board, directly responsible for appointing, compensating, and overseeing the registered public accounting firm, including resolving disagreements between management and the auditor. The firm reports directly to the audit committee. Management, including the CFO, does not hold that authority. Shareholders may ratify the choice in practice, but the statute assigns the responsibility to the committee. The PCAOB oversees audit firms; it does not engage auditors for issuers.

Assessing Risk and Developing a Planned Response

Under Section 302 of the Sarbanes-Oxley Act, the principal executive and financial officers of an issuer certify each annual and quarterly report. Which statement is part of that certification?

  • a.The issuer has adopted a code of ethics that applies to all of its employees
  • b.No fraud of any size occurred at the issuer during the period covered by the report
  • c.The signing officers are responsible for establishing and maintaining internal controls✓
  • d.The external auditor has attested to management's internal control assessment

Section 302(a)(4) requires the signing officers to certify that they are responsible for establishing and maintaining internal controls, have designed them so that material information reaches them, and have evaluated their effectiveness. Auditor attestation comes from Section 404(b), not from the officers' certification. Section 406 requires disclosure of whether a code of ethics exists for senior financial officers, not all employees. The officers disclose fraud involving management or key control employees to the auditors and audit committee; they do not certify that no fraud of any size occurred.

Assessing Risk and Developing a Planned Response

Which requirement comes from Section 407 of the Sarbanes-Oxley Act?

  • a.Certification of each periodic report by the CEO and the CFO
  • b.Disclosure of whether the audit committee has a financial expert✓
  • c.Auditor attestation to management's internal control assessment
  • d.A rule that every member of the audit committee must be a licensed CPA

Section 407 directs the SEC to require each issuer to disclose whether its audit committee includes at least one member who is a financial expert and, if not, why not. It does not require committee members to be CPAs. Auditor attestation on internal control comes from Section 404(b), and officer certification of periodic reports comes from Section 302.

Assessing Risk and Developing a Planned Response

For purposes of GAAS, an entity's system of internal control consists of five interrelated components. Which list names them?

  • a.Control environment, risk assessment process, monitoring process, information and communication, control activities✓
  • b.Governance, fraud risk assessment, information system, physical controls, external audit
  • c.Tone at the top, risk assessment process, authorization, reconciliations, monitoring process
  • d.Control environment, segregation of duties, IT general controls, internal audit, control activities

AU-C 315.12 defines the system of internal control as having five components: the control environment, the entity's risk assessment process, the entity's process to monitor the system of internal control, the information system and communication, and control activities. These match the five COSO components. Segregation of duties, authorizations, reconciliations, and IT general controls are types of control activities, not separate components. Internal audit is part of monitoring, and the external auditor is not part of the entity's system at all.

Assessing Risk and Developing a Planned Response

A purchasing clerk and a receiving supervisor agree to record receipts of goods that were never delivered, so the automated three-way match reports no exceptions. This situation best illustrates which inherent limitation of internal control?

  • a.A reviewer who misunderstands the purpose of an exception report
  • b.Management's decision to accept a known risk as a cost matter
  • c.Faulty human judgment in how the control was designed
  • d.Circumvention of controls by collusion of two or more people✓

AU-C 315 appendix C (par. 24) notes that controls can be circumvented by the collusion of two or more people or by inappropriate management override. Here two employees acting together defeated a control that was properly designed. Faulty judgment in design and a reviewer who does not understand an exception report are other limitations listed in paragraph 23, but they do not describe this case. Management's choice to accept a risk is discussed in paragraph 25 and is not what happened here.

Assessing Risk and Developing a Planned Response

Which of the following is a general IT control rather than an information-processing control?

  • a.A three-way match of purchase order, receiving report, and invoice
  • b.An automated edit check rejecting sales orders over credit limits
  • c.Periodic review of user access rights to the ERP system✓
  • d.System calculation of monthly depreciation for each fixed asset

AU-C 315.12 defines general IT controls as controls over the entity's IT processes that support the continued proper operation of the IT environment, and it names those processes as managing access, managing program changes, and managing IT operations. A review of user access rights is an access control. Edit checks, three-way matches, and automated calculations act directly on individual transactions and are information-processing controls.

Assessing Risk and Developing a Planned Response

A SOC 1 type 2 report for a payroll processor lists complementary user entity controls, including the user entity's review of payroll change reports. What should the auditor of the user entity, a nonissuer, do about these controls?

  • a.If they address relevant risks, understand whether the entity designed and implemented them✓
  • b.Ignore them, since complementary user entity controls are the service organization's duty
  • c.Ask the service auditor to test these controls at the user entity during its next examination
  • d.Rely on the service auditor's opinion, which already covers the user entity's controls

AU-C 402.14c requires the user auditor to determine whether complementary user entity controls address risks of material misstatement in relevant assertions and, if so, to understand whether the user entity has designed and implemented them. By definition these are controls the service organization assumes the user entity will put in place, so the service auditor's opinion does not cover them. The service auditor does not test controls at user entities.

Assessing Risk and Developing a Planned Response

The auditor of a nonissuer used a SOC 1 type 2 report as audit evidence and is issuing an unmodified opinion. Under AU-C 402, may the auditor's report refer to the service auditor's work?

  • a.Yes, in order to divide responsibility between the two auditors
  • b.Yes, reference is required whenever such a report is used as evidence
  • c.Yes, provided the service auditor's name and report date are stated
  • d.No, the report should not refer to the service auditor's work✓

AU-C 402.21 states that the user auditor should not refer to the work of a service auditor in a report containing an unmodified opinion. Paragraph .22 allows a reference only when it helps explain a modified opinion, and even then the report must say the reference does not reduce the user auditor's responsibility. The user auditor never divides responsibility with a service auditor.

Assessing Risk and Developing a Planned Response

In an audit of a nonissuer, no specific risks of material misstatement due to fraud have been identified. Which procedure does AU-C 240 still require in order to address the risk of management override of controls?

  • a.Confirming every related party balance with the counterparty
  • b.Testing the appropriateness of journal entries and other adjustments✓
  • c.Obtaining a separate representation letter from the board
  • d.Observing a surprise count of all petty cash funds

AU-C 240.32 requires, apart from any specific fraud risks, procedures to test journal entries and other adjustments, to review accounting estimates for bias (including a retrospective review), and to evaluate the business rationale of significant unusual transactions. Confirming related party balances and counting petty cash may be useful in some audits but are not required responses to override. A separate board representation letter is not required by AU-C 240.

Want these explained in order? CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Assessing Risk and Developing a Planned Response

A nonissuer's sales managers receive bonuses only if quarterly revenue beats budget, and the budget was raised 30% this year even though the market is flat. Using the fraud risk factor categories in AU-C 240, these facts primarily indicate

  • a.an attitude or rationalization for fraud
  • b.an incentive or pressure to commit fraud✓
  • c.an actual fraud that must be reported to regulators
  • d.an opportunity to misappropriate assets

AU-C 240.11 and its appendix A group fraud risk factors by incentive or pressure, perceived opportunity, and attitude or rationalization. Compensation that depends on hitting aggressive revenue targets is an incentive or pressure to overstate revenue. Nothing in the facts shows a weakness that creates an opportunity, or an attitude that justifies misconduct. Risk factors are conditions, not evidence that fraud has occurred.

Assessing Risk and Developing a Planned Response

At a small nonissuer, one employee opens the mail, deposits customer checks, posts cash receipts to customer accounts, and reconciles the bank account. Using the fraud risk factor categories in AU-C 240, this primarily indicates

  • a.a significant unusual transaction
  • b.an opportunity to misappropriate assets✓
  • c.an incentive or pressure to misstate revenue
  • d.an attitude or rationalization for fraud

Fraud risk factors in AU-C 240 fall into incentive or pressure, perceived opportunity, and attitude or rationalization. Letting one person both handle cash and keep the related records, with no independent reconciliation, is inadequate segregation of duties, which creates an opportunity to steal and conceal it. The facts say nothing about pressure or attitude, and routine cash receipts are not significant unusual transactions.

Assessing Risk and Developing a Planned Response

In an audit of a nonissuer, the auditor concludes that the presumed risk of fraud in revenue recognition does not apply, because the entity earns only fixed monthly rent under a few long-term leases. Under AU-C 240, what must the auditor do?

  • a.Document the reasons for that conclusion✓
  • b.Still treat revenue as a significant fraud risk
  • c.Disclose the rebuttal in the auditor's report
  • d.Obtain approval from those charged with governance

AU-C 240.26 establishes a presumption that fraud risks exist in revenue recognition, and paragraph .A35 recognizes that the presumption may be rebutted. When it is, paragraph .46 requires the auditor to document the reasons for that conclusion. Governance approval is not required, the auditor does not have to keep treating revenue as a fraud risk once the presumption is overcome, and the conclusion is not reported in the auditor's report.

Assessing Risk and Developing a Planned Response

The auditor of a nonissuer uses 5% of pretax income from continuing operations as a starting point for materiality for the financial statements as a whole. Pretax income is $1,800,000, including a $600,000 one-time gain that the auditor decides to exclude as exceptional. What is the starting-point materiality?

  • a.$30,000
  • b.$60,000✓
  • c.$120,000
  • d.$90,000

AU-C 320.A8 notes that when an exceptional item distorts profit before tax, the auditor may conclude that materiality is better based on a normalized profit figure. Normalized pretax income is $1,800,000 - $600,000 = $1,200,000, and 5% of that is $60,000. Using the unadjusted $1,800,000 gives $90,000, applying 5% to the gain alone gives $30,000, and adding the gain instead of removing it ($2,400,000) gives $120,000. The percentage is the auditor's judgment; GAAS does not prescribe one.

Assessing Risk and Developing a Planned Response

Why does an auditor set performance materiality at an amount less than materiality for the financial statements as a whole?

  • a.To limit the risk that uncorrected plus undetected misstatements exceed materiality✓
  • b.To fix the level at which management may decline to record proposed adjustments
  • c.To set the amount below which misstatements are clearly trivial and need not be accumulated
  • d.To set the threshold above which a misstatement must be described in the auditor's report

AU-C 320.09 defines performance materiality as the amount set below overall materiality to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds materiality for the financial statements as a whole. The clearly trivial threshold is a separate, much smaller amount under AU-C 450. Misstatements are not described in the report based on performance materiality, and management does not get a threshold for refusing corrections.

Assessing Risk and Developing a Planned Response

During fieldwork on a nonissuer audit, actual revenue proves to be 20% below the forecast used to set materiality, and the auditor lowers materiality for the financial statements as a whole. Under AU-C 320, what else should the auditor do?

  • a.Reconsider performance materiality and the planned procedures✓
  • b.Keep performance materiality unchanged, since it was set during planning
  • c.Document the change only if materiality fell by more than half
  • d.Raise the clearly trivial threshold to offset the lower materiality

AU-C 320.12 requires the auditor to revise materiality when information arises that would have led to a different amount initially. Paragraph .13 then requires the auditor to determine whether performance materiality needs revising and whether the nature, timing, and extent of further audit procedures remain appropriate. Freezing performance materiality ignores that requirement, raising the trivial threshold works in the wrong direction, and the standard sets no 50% trigger for documentation.

Assessing Risk and Developing a Planned Response

A nonissuer installed a new leasing system in March, and from then on its right-of-use assets were calculated under a revised method. Under AU-C 315, which inherent risk factor does this most directly represent?

  • a.Uncertainty
  • b.Subjectivity
  • c.Susceptibility to fraud
  • d.Change✓

AU-C 315.12 lists the inherent risk factors as complexity, subjectivity, change, uncertainty, and susceptibility to misstatement due to management bias or other fraud risk factors. A new system and a new calculation method during the period are events that alter how the balance is produced, which is the change factor. Uncertainty concerns amounts that cannot be measured precisely, subjectivity concerns limits on knowledge and judgment in preparing the information, and nothing here points to bias or fraud.

Assessing Risk and Developing a Planned Response

Under AU-C 315 as revised by SAS No. 145, an identified risk of material misstatement is a significant risk when

  • a.its combined risk, after considering controls, is assessed as high
  • b.its inherent risk is close to the upper end of the spectrum of inherent risk✓
  • c.management has not designed any controls that address the risk
  • d.the related account balance exceeds materiality for the statements as a whole

AU-C 315.12 defines a significant risk as one whose inherent risk assessment is close to the upper end of the spectrum of inherent risk, based on the combination of likelihood and magnitude, or one that other AU-C sections require to be treated as significant. The assessment is made on inherent risk, before controls, so a combined risk that reflects controls is the wrong measure. Account size alone does not make a risk significant, and missing controls affect control risk, not the significant-risk determination.

Assessing Risk and Developing a Planned Response

For a relevant assertion about inventory existence, the auditor of a nonissuer does not plan to test the operating effectiveness of controls. Under AU-C 315, how should control risk be assessed?

  • a.At the maximum, so that risk of misstatement equals inherent risk✓
  • b.It need not be assessed; only a combined risk is required
  • c.As moderate, which is the default when controls are not tested
  • d.As low, if the controls were found to be designed and implemented

AU-C 315.38 requires control risk to be assessed based on the auditor's understanding of controls and plan to test them. If the auditor does not plan to test operating effectiveness, control risk is assessed at the maximum so that the risk of material misstatement equals the inherent risk assessment. Evaluating design and implementation is not a test of operating effectiveness, there is no moderate default, and SAS No. 145 requires separate assessments of inherent and control risk.

Assessing Risk and Developing a Planned Response

The auditor of a nonissuer plans to rely on controls that address a significant risk in revenue. The controls were tested last year with no deviations and have not changed. Under AU-C 330, what is required this year?

  • a.Test the controls at least once in every third audit
  • b.Confirm through inquiry alone that the controls still operate
  • c.Rely on last year's tests, since the controls have not changed
  • d.Test those controls' operating effectiveness this period✓

AU-C 330.15 requires the auditor to test controls over a significant risk in the current period if the auditor intends to rely on them. The once-in-every-third-audit relief in paragraph .14 does not extend to controls over significant risks. Inquiry alone is not sufficient to test operating effectiveness (AU-C 330.A28).

Want these explained in order? CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Assessing Risk and Developing a Planned Response

Certain controls that do not address a significant risk were tested in a prior audit and have not changed. AU-C 330 allows the auditor of a nonissuer to use that prior-year evidence if

  • a.management states in writing that none of the controls has changed during the year
  • b.the controls were tested in the immediately preceding audit and in no other period
  • c.continuing relevance is established and each is tested at least every third audit✓
  • d.the controls are automated and the general IT controls were tested in any earlier year

AU-C 330.14 requires the auditor to establish the continuing relevance of prior evidence through inquiry combined with observation or inspection. If nothing has changed, the controls must be tested at least once in every third audit, with some controls tested each year so that all testing does not fall in a single year. Automation and management's written statements do not replace these steps.

Assessing Risk and Developing a Planned Response

The auditor of a nonissuer tested the controls over a significant account balance and found them operating effectively. Under AU-C 330, which statement about substantive procedures is correct?

  • a.No substantive procedures at all are needed for that account balance
  • b.Substantive procedures are still needed for its relevant assertions✓
  • c.Only overall-review analytical procedures are needed for it
  • d.Substantive procedures are needed only if deviations were found in testing

AU-C 330.18 requires substantive procedures for each relevant assertion of each significant class of transactions, account balance, and disclosure, regardless of the assessed level of control risk. Effective controls can reduce the extent of substantive work but cannot remove it entirely. The overall-review analytics required by AU-C 520.06 are a separate requirement and do not replace substantive procedures.

Assessing Risk and Developing a Planned Response

The auditor of a nonissuer assesses a high risk of material misstatement at the financial statement level because of a weak control environment. Which is an appropriate overall response?

  • a.Rely more on tests of controls so that substantive work can be reduced
  • b.Move more substantive procedures from year-end to an interim date
  • c.Assign more experienced staff and add unpredictability to the procedures✓
  • d.Use smaller samples, since the high risk has already been identified

AU-C 330.05 requires overall responses to financial statement level risks, and AU-C 240.29 names assigning personnel with suitable skill and experience and building in unpredictability as responses. A weak control environment calls for more work at or near period-end rather than at interim dates, and it undermines reliance on controls. Higher risk requires more persuasive evidence, which generally means larger, not smaller, samples.

Assessing Risk and Developing a Planned Response

Under AU-C 610, the external auditor of a nonissuer may not use the work of the internal audit function to obtain audit evidence if the auditor determines that the function

  • a.reports to the audit committee rather than to the chief financial officer of the entity
  • b.lacks a systematic and disciplined approach, including quality management✓
  • c.performed its work at an interim date instead of at year-end
  • d.is staffed by the entity's employees rather than an outside provider

AU-C 610.14 prohibits using the function's work if its organizational status and policies do not support objectivity, if it lacks competence, or if it does not apply a systematic and disciplined approach including quality management. Reporting to the audit committee strengthens objectivity rather than weakening it. Interim timing and in-house staffing are matters the auditor considers but are not grounds for prohibition.

Assessing Risk and Developing a Planned Response

Before using the work of an auditor's external specialist to value complex derivatives in a nonissuer audit, AU-C 620 requires the auditor to evaluate whether the specialist has the necessary

  • a.fee arrangement approved by the entity's audit committee
  • b.competence, capabilities, and objectivity✓
  • c.CPA license in the state where the entity is located
  • d.independence under the AICPA Code of Professional Conduct

AU-C 620.09 requires the auditor to evaluate whether the auditor's specialist has the competence, capabilities, and objectivity needed for the auditor's purposes, and for an external specialist this includes inquiring about interests and relationships that could threaten objectivity. The standard speaks of objectivity, not independence under the AICPA Code. It does not require a CPA license or audit committee approval of fees; specialists are by definition experts in fields other than accounting or auditing.

Assessing Risk and Developing a Planned Response

A nonissuer's pension obligation is calculated by an actuary the entity engaged. To the extent necessary given the significance of the actuary's work, what does AU-C 501 require the auditor to do?

  • a.Assess its competence, capabilities, and objectivity, understand its work, and evaluate that work✓
  • b.Accept the actuary's figures without further work, as long as the actuary holds a professional credential
  • c.Refer to the actuary in the auditor's report so that responsibility for the obligation is shared
  • d.Engage a second, independent actuary to recompute the entire obligation as a substitute for testing

The entity's actuary is a management's specialist. AU-C 501.27 requires the auditor, to the extent necessary, to evaluate that specialist's competence, capabilities, and objectivity, obtain an understanding of the work, and evaluate its appropriateness as audit evidence. A credential is only one input to that evaluation. Hiring a second actuary is sometimes useful but is not required. The auditor's report does not refer to a specialist to share responsibility.

Assessing Risk and Developing a Planned Response

In an audit of a nonissuer, what is the auditor's responsibility for laws and regulations generally recognized to have a direct effect on the determination of material amounts and disclosures, such as tax laws?

  • a.None, unless noncompliance happens to come to the auditor's attention
  • b.Perform only inquiries of management and inspect any correspondence with regulators
  • c.Obtain sufficient appropriate evidence about the amounts they determine✓
  • d.Provide assurance that the entity complied with every provision of those laws

AU-C 250.13 requires sufficient appropriate audit evidence regarding material amounts and disclosures determined by laws and regulations that have a direct effect, such as tax and pension laws. Limited procedures such as inquiry and inspection of regulatory correspondence are the requirement for other laws under paragraph .14. An audit does not provide assurance on compliance with every legal provision, and the auditor's responsibility for direct-effect laws is active, not passive.

Assessing Risk and Developing a Planned Response

A nonissuer manufacturer must keep an environmental operating permit. The permit rules do not directly determine any financial statement amounts, but losing the permit would halt operations. Under AU-C 250, which procedures must the auditor perform regarding compliance with these rules?

  • a.Inquire about compliance and inspect correspondence with the permit authority✓
  • b.Obtain a written legal opinion on compliance from the entity's external legal counsel
  • c.None, because such laws are outside a financial statement audit
  • d.Test compliance with every permit condition to obtain reasonable assurance on compliance

Permit requirements that are fundamental to operations but have no direct effect on amounts fall in the second category of laws in AU-C 250.06b. For these, paragraph .14 requires the auditor to inquire of management and, when appropriate, those charged with governance about compliance, and to inspect correspondence with the licensing or regulatory authorities. The auditor is not required to obtain reasonable assurance of compliance or a legal opinion, but the laws are not outside the audit either, since noncompliance could have a material effect.

Assessing Risk and Developing a Planned Response

Which is an indicator of possible management bias in accounting estimates, as described in AU-C 540?

  • a.Selecting point estimates that show a pattern of optimism✓
  • b.Using a specialist to develop a complex estimate
  • c.Revising an estimate when new market data arrive
  • d.Disclosing the estimation uncertainty in the notes

AU-C 540.A134 lists indicators of possible management bias, including changing an estimate or method on a subjective claim of changed circumstances, choosing assumptions or data that favor management's objectives, and selecting point estimates that show a pattern of optimism or pessimism. Using a specialist, updating estimates for new market information, and disclosing uncertainty are normal parts of a sound estimation process.

Assessing Risk and Developing a Planned Response

AU-C 540 requires the auditor to review the outcome of prior-period accounting estimates. What is the main purpose of this review?

  • a.To help identify and assess current-period risks of material misstatement✓
  • b.To measure management's accuracy for disclosure in the current report
  • c.To evaluate whether prior-year audit judgments were appropriate
  • d.To decide whether the prior-year financial statements must now be restated

AU-C 540.13 requires the review to assist in identifying and assessing risks of material misstatement in the current period. It states that the review is not meant to call into question prior-period judgments that were appropriate given the information available when they were made. Its purpose is not to trigger restatements or to produce a disclosure.

Assessing Risk and Developing a Planned Response

In an audit of a nonissuer, which procedure does AU-C 550 require specifically to find related party relationships or transactions that management has not disclosed to the auditor?

  • a.Recomputing depreciation on all assets purchased from new vendors during the year
  • b.Inspecting bank and legal confirmations and minutes for signs of undisclosed related parties✓
  • c.Sending positive confirmations to the ten largest customers about their balances
  • d.Observing the physical inventory count at the entity's main warehouse at year-end

AU-C 550.17 requires the auditor to remain alert when inspecting records or documents for arrangements that may indicate undisclosed related party relationships or transactions. It specifically requires inspecting bank and legal confirmations and minutes of meetings of shareholders and those charged with governance. Customer balance confirmations, depreciation recalculations, and inventory observation address other assertions and are not the required procedure.

Assessing Risk and Developing a Planned Response

An entity expended $2.4 million of federal awards, all under a single federal program that is not research and development. The program's terms do not require a financial statement audit. Under 2 CFR 200.501, which audit may the entity elect?

  • a.A review of its schedule of federal expenditures
  • b.No audit, because only one program is involved
  • c.A program-specific audit✓
  • d.An agreed-upon procedures engagement instead

2 CFR 200.501(c) allows a program-specific audit under 200.507 when the entity expends federal awards under only one program (excluding research and development) and the program's rules do not require a financial statement audit. Because expenditures exceed $1,000,000, an audit of some kind is still required. Agreed-upon procedures and reviews are not audits under subpart F.

Assessing Risk and Developing a Planned Response

A data analytic run on a nonissuer's full journal entry population flags 14 manual entries posted by the CFO on a Sunday after year-end, each crediting revenue just below the approval limit. What is the most appropriate audit response?

  • a.Treat them as higher risk and examine their support and business purpose✓
  • b.Rely on the analytic output alone as sufficient evidence about the entries
  • c.Conclude there is no issue, because the analytic covered all of the entries
  • d.Exclude the entries from testing, since each is below the approval limit

AU-C 240.32a requires testing the appropriateness of journal entries, considering fraud risk indicators and entries made at period-end. Entries posted by a senior officer on a weekend, after year-end, and sized just under an approval threshold show several risk characteristics. The analytic finds items to investigate but does not by itself provide evidence that they are appropriate. Being under the approval limit is itself a red flag, not a reason to skip testing.

Report