🇺🇸 Certified Public Accountant (CPA) · subject
Certified Public Accountant (CPA) Auditing and Attestation (AUD) — Core Syllabus
Every chapter and topic of Auditing and Attestation (AUD) — Core examined in Certified Public Accountant (CPA) — 5 chapters, 33 topics and 30 sub-topics, plus 51 flashcards written against it.
Auditing and Attestation (AUD) — Core syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Auditing and Attestation (AUD) — Core in Certified Public Accountant (CPA), not a summary of it.
-
Ethics, Professional Responsibilities, and General Principles
5 topics- AICPA Code of Professional Conduct
- Conceptual framework approach and threats to compliance
- Integrity, objectivity, and due care principles
- Acts discreditable to the profession
- Independence requirements
- Covered members and financial interests
- Non-attest services and prohibited relationships
- SEC and PCAOB independence rules for issuers
- Requirements of regulatory bodies
- GAO Government Auditing Standards (Yellow Book)
- Department of Labor rules for employee benefit plan audits
- PCAOB versus AICPA standard-setting authority
- Quality management at the engagement and firm level
- Terms of engagement and engagement letters
- AICPA Code of Professional Conduct
-
Risk Assessment and Engagement Planning
7 topics- Audit risk model
- Inherent risk, control risk, and detection risk
- Risk of material misstatement at assertion level
- Materiality determination and reassessment
- Understanding the entity and its environment
- Internal control components (COSO framework)
- Control environment and entity-level controls
- Information systems and IT general controls
- Identifying and evaluating control deficiencies
- Fraud risk assessment and brainstorming
- Fraud triangle and presumed fraud risks
- Management override of controls
- Audit strategy and the overall audit plan
- Using the work of specialists and internal audit
- Audit risk model
-
Performing Further Procedures and Obtaining Evidence
8 topics- Sufficient appropriate audit evidence and assertions
- Tests of controls versus substantive procedures
- Audit sampling
- Attributes sampling for tests of controls
- Variables and monetary-unit sampling for substantive tests
- Sampling risk and evaluation of results
- Analytical procedures and data analytics
- Substantive testing of significant accounts
- Cash, receivables, and revenue
- Inventory observation and valuation
- Estimates and fair value measurements
- Confirmations and external evidence
- Subsequent events and going concern evaluation
- Written representations and the management representation letter
-
Forming Conclusions and Reporting
7 topics- Forming the audit opinion
- Unmodified opinion structure
- Qualified, adverse, and disclaimer of opinion
- Key and critical audit matters
- AICPA key audit matters
- PCAOB critical audit matters
- Emphasis-of-matter and other-matter paragraphs
- Reports on internal control over financial reporting
- Group audits and component auditors
- Comparative statements and other information in annual reports
- Communications with those charged with governance
- Forming the audit opinion
-
Other Engagements, Services, and SOC Reports
6 topics- Reviews of financial statements (SSARS)
- Compilations and preparation engagements
- Attestation engagements (SSAE)
- Examination, review, and agreed-upon procedures
- Prospective financial information
- System and Organization Controls (SOC) reports
- SOC 1 controls relevant to financial reporting
- SOC 2 trust services criteria
- Interim financial information reviews
- Single Audits under the Uniform Guidance
Auditing and Attestation (AUD) — Core flashcards for Certified Public Accountant (CPA)
22 of 51 cards from the Auditing and Attestation (AUD) — Core deck — real questions with worked answers.
What are the six principles underlying the AICPA Code of Professional Conduct?
Responsibilities, The Public Interest, Integrity, Objectivity and Independence, Due Care, and Scope and Nature of Services.
Under the AICPA Conceptual Framework approach, what are the three steps a member uses to evaluate threats to compliance?
Identify threats, evaluate the significance of each threat, and (if not at an acceptable level) apply safeguards to eliminate or reduce the threat.
Name the seven broad categories of threats to compliance under the AICPA Code of Professional Conduct.
Adverse interest, advocacy, familiarity, management participation, self-interest, self-review, and undue influence threats.
Under the AICPA Code, what is the difference between independence in fact and independence in appearance?
Independence in fact is the actual unbiased mental attitude in performing the engagement; independence in appearance is the avoidance of circumstances that would cause a reasonable, informed third party to conclude that integrity, objectivity, or skepticism was compromised.
For which types of engagements is independence required, and for which is it not?
Independence is required for audits, reviews, and other attest engagements (examinations, agreed-upon procedures). It is NOT required for compilations (disclosure required), tax, or consulting/nonattest services.
Under the SEC/PCAOB independence rules, what is the partner rotation requirement for the lead and concurring (engagement quality) partners on an issuer audit?
The lead and concurring partners must rotate off after 5 years and observe a 5-year 'time-out' (cooling-off) period.
What is the one-year cooling-off period rule for SEC issuer audits?
A member of the audit engagement team cannot accept a financial reporting oversight role (e.g., CEO, CFO, controller) with the audit client until at least one annual audit period has passed after they last participated in the audit.
Under SEC independence rules, may an auditor of an issuer provide bookkeeping or financial system design/implementation services to that audit client?
No. The SEC prohibits these (and several other nonaudit services such as internal audit outsourcing, actuarial, and management functions) for audit clients that are issuers.
Who provides audit oversight and standard-setting for public companies (issuers) versus nonissuers in the U.S.?
The PCAOB sets auditing standards and oversees audits of issuers; the AICPA's Auditing Standards Board (ASB) issues SAS (GAAS) for nonissuers.
Under the AICPA Code, when does a covered member's direct financial interest impair independence?
Any direct financial interest in an attest client impairs independence regardless of materiality. An indirect financial interest impairs independence only if material.
What are the two components/objectives of a system of quality management at the firm level under SQMS No. 1?
(1) Reasonable assurance the firm and its personnel fulfill responsibilities per professional standards and legal/regulatory requirements; and (2) reports issued are appropriate in the circumstances.
Name the eight components of a firm's system of quality management under SQMS No. 1.
The firm's risk assessment process, governance and leadership, relevant ethical requirements, acceptance and continuance of client relationships, engagement performance, resources, information and communication, and the monitoring and remediation process.
What is the engagement quality review (EQR) and when is it required?
An EQR is an objective evaluation of the significant judgments and conclusions of the engagement team by a qualified reviewer not on the team, completed before the report is released; it is required for audits of issuers and for engagements the firm's quality management policies designate.
What is the difference between 'quality management at the firm level' and 'quality management at the engagement level'?
Firm level (SQMS 1) establishes the overall system of quality management; engagement level (SAS 146 / AU-C 220) is the engagement partner's responsibility to manage and achieve quality on the specific engagement within that system.
What are the typical preconditions for an audit that the auditor must establish before accepting an engagement?
Determine the financial reporting framework is acceptable, and obtain management's agreement that it acknowledges its responsibilities for the financial statements, internal control, and providing the auditor access to information and personnel.
List the key elements that must be included in an audit engagement letter.
Objective and scope of the audit, responsibilities of the auditor and of management, identification of the applicable financial reporting framework, expected form and content of reports, and a statement that there is an inherent risk material misstatements may not be detected.
State the audit risk model formula.
$AR = IR \times CR \times DR$, where audit risk equals inherent risk times control risk times detection risk.
In the audit risk model, what is the relationship between detection risk and the risk of material misstatement (RMM)?
They are inversely related: as RMM ($IR \times CR$) increases, the acceptable level of detection risk decreases, requiring more or more effective substantive procedures.
Define inherent risk and control risk.
Inherent risk is the susceptibility of an assertion to material misstatement before considering controls; control risk is the risk that a material misstatement will not be prevented or detected and corrected on a timely basis by the entity's internal control.
How does the auditor reduce detection risk when it must be set low?
By increasing the nature (more effective/reliable procedures), timing (perform at year-end rather than interim), and extent (larger sample sizes) of substantive procedures.
Distinguish overall materiality, performance materiality, and the clearly trivial threshold.
Overall (planning) materiality is the misstatement level affecting users' decisions for the statements as a whole; performance materiality is set below overall materiality to reduce aggregation risk for procedures; clearly trivial is a much smaller amount below which misstatements need not be accumulated.
What common benchmarks are used to determine overall materiality?
Commonly a percentage of a chosen benchmark such as income before tax (e.g., ~5%), total revenue, total assets, or net assets, selected based on the nature of the entity and users' focus.
Planning Auditing and Attestation (AUD) — Core for Certified Public Accountant (CPA)
Auditing and Attestation (AUD) — Core is about 23% of the Certified Public Accountant (CPA) syllabus by topic count — 33 of 142 topics, spread over 5 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 30 hours.
The heaviest chapters are Performing Further Procedures and Obtaining Evidence (8 topics), Risk Assessment and Engagement Planning (7 topics), Forming Conclusions and Reporting (7 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Auditing and Attestation (AUD) — Core (Certified Public Accountant (CPA)) FAQ
What is in the Certified Public Accountant (CPA) Auditing and Attestation (AUD) — Core syllabus?
Auditing and Attestation (AUD) — Core is split into 5 chapters — Ethics, Professional Responsibilities, and General Principles, Risk Assessment and Engagement Planning, Performing Further Procedures and Obtaining Evidence, Forming Conclusions and Reporting and Other Engagements, Services, and SOC Reports, containing 33 topics and 30 sub-topics in total.
How many chapters are there in Auditing and Attestation (AUD) — Core for Certified Public Accountant (CPA)?
5 chapters. Auditing and Attestation (AUD) — Core accounts for about 23% of the topics in the whole Certified Public Accountant (CPA) syllabus (33 of 142).
How long should I spend on Auditing and Attestation (AUD) — Core for Certified Public Accountant (CPA)?
Budget around 30 hours for a first pass through Auditing and Attestation (AUD) — Core — about 45 minutes per topic plus 12 minutes per sub-topic across its 33 topics. Add revision cycles on top.
Are there flashcards for Certified Public Accountant (CPA) Auditing and Attestation (AUD) — Core?
Yes — a 51-card Auditing and Attestation (AUD) — Core deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.