🇺🇸 Certified Public Accountant (CPA) · flashcards
Certified Public Accountant (CPA) Auditing and Attestation (AUD) — Core Flashcards
51 question-and-answer cards covering Auditing and Attestation (AUD) — Core as it is examined in Certified Public Accountant (CPA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Auditing and Attestation (AUD) — Core deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
Define the COSO 'control environment' component.
The set of standards, processes, and structures that provide the foundation for internal control — including integrity and ethical values, board oversight, organizational structure, commitment to competence, and accountability ('tone at the top').
What is the fraud triangle, and what are its three elements?
The fraud triangle explains conditions present when fraud occurs: incentive/pressure, opportunity, and rationalization/attitude.
What are the two main types of misstatement arising from fraud the auditor considers?
Fraudulent financial reporting (intentional misstatement of amounts/disclosures to deceive users) and misappropriation of assets (theft of an entity's assets, i.e., defalcation).
What is the purpose of the required fraud 'brainstorming' session among the engagement team?
To discuss how and where the financial statements might be susceptible to material misstatement due to fraud, emphasizing professional skepticism and how management could perpetrate and conceal fraud; it is required and may not be omitted.
Which fraud risk is presumed significant on every audit, and how must the auditor respond?
Improper revenue recognition is a presumed (rebuttable) fraud risk, and the auditor must address it. The risk of management override of controls is also always present, requiring procedures such as testing journal entries, reviewing estimates for bias, and evaluating significant unusual transactions.
Distinguish the audit strategy from the audit plan.
The overall audit strategy sets the scope, timing, and direction of the audit and guides development of the more detailed audit plan; the audit plan describes the nature, timing, and extent of risk assessment procedures, further audit procedures, and other required procedures.
When using the work of a management's specialist, what must the auditor evaluate?
The competence, capabilities, and objectivity of the specialist; obtain an understanding of the specialist's work; and evaluate the appropriateness of that work as audit evidence for the relevant assertion.
Can the auditor use the work of the entity's internal audit function to obtain audit evidence, and does it reduce the auditor's responsibility?
Yes, the external auditor may use internal audit work (or direct assistance) after evaluating its objectivity, competence, and systematic/disciplined approach, but the external auditor retains sole responsibility for the audit opinion.
What are the two ways an external auditor may make use of the internal audit function?
(1) Using the body of work already performed by internal audit as audit evidence; and (2) using internal auditors to provide direct assistance under the external auditor's direction, supervision, and review.
What two qualities must audit evidence possess to support the auditor's opinion?
It must be sufficient (a measure of quantity) and appropriate (a measure of quality — relevance and reliability).
List factors that generally increase the reliability of audit evidence.
Evidence from independent external sources, evidence from effective internal control, evidence obtained directly by the auditor, evidence in documentary/written form, and original documents over copies.
List the assertions about classes of transactions and events during the period.
Occurrence, completeness, accuracy, cutoff, and classification (and presentation).
List the assertions about account balances at period end.
Existence, rights and obligations, completeness, and valuation and allocation (accuracy, valuation, and allocation).
Distinguish tests of controls from substantive procedures.
Tests of controls evaluate the operating effectiveness of controls in preventing/detecting material misstatements (supporting a lower control risk); substantive procedures detect material misstatements at the assertion level and consist of tests of details and substantive analytical procedures.
When are tests of controls required to be performed?
When the auditor intends to rely on the operating effectiveness of controls to reduce substantive testing, or when substantive procedures alone cannot provide sufficient appropriate evidence (e.g., highly automated processing with little documentary evidence).
What is the difference between a Type I and Type II error in attribute (controls) sampling?
Type I (risk of assessing control risk too high / underreliance) leads to inefficiency; Type II (risk of assessing control risk too low / overreliance) leads to ineffectiveness because the auditor relies on controls that are not effective.
What two sampling risks affect substantive tests of details?
Risk of incorrect rejection (affects efficiency) and risk of incorrect acceptance (affects effectiveness — the more serious risk because it can lead to an incorrect audit opinion).
In attribute sampling, how is the sample deviation rate compared to thresholds to reach a conclusion?
The auditor computes the upper deviation rate (sample deviation rate plus allowance for sampling risk) and compares it to the tolerable deviation rate; if the upper deviation rate does not exceed the tolerable rate, the control can be relied upon.
What three factors increase the required sample size in attribute sampling?
A higher expected population deviation rate, a lower tolerable deviation rate, and a lower acceptable risk of overreliance (higher desired confidence) each increase sample size.
What are the four basic analytical procedure techniques, and at which audit phases are analytics required?
Trend analysis, ratio analysis, reasonableness/regression, and common-size (vertical) analysis. Analytical procedures are required during risk assessment (planning) and during the overall final review; they are optional as substantive procedures.
How does data analytics enhance substantive testing compared with traditional sampling?
Data analytics can test 100% of a population (full-population testing) to identify outliers, anomalies, and exceptions, improving precision and the auditor's ability to detect misstatements relative to testing only a sample.
What is the positive versus negative confirmation, and when may negatives be used?
A positive confirmation asks the recipient to respond whether or not they agree; a negative confirmation asks for a response only if they disagree. Negatives may be used only when RMM is low, controls are effective, many small homogeneous balances exist, and a low exception rate is expected.
Why are external confirmations considered strong audit evidence, and which assertion do accounts receivable confirmations primarily test?
They are obtained directly by the auditor from independent third parties, increasing reliability. AR confirmations primarily test the existence assertion (not completeness or valuation/collectibility).
What should the auditor do when no response is received to a positive confirmation request?
Send second (and possibly third) requests, and for remaining nonresponses perform alternative procedures such as examining subsequent cash receipts, shipping documents, and sales invoices to obtain evidence about the balance.
What this deck covers
The Auditing and Attestation (AUD) — Core deck follows the Certified Public Accountant (CPA) Auditing and Attestation (AUD) — Core syllabus — 5 chapters and 33 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 10.2 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 213 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Auditing and Attestation (AUD) — Core flashcards FAQ
How many Auditing and Attestation (AUD) — Core flashcards are in this Certified Public Accountant (CPA) deck?
51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Public Accountant (CPA) flashcards free?
Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.
What do the Auditing and Attestation (AUD) — Core cards cover?
They follow the Certified Public Accountant (CPA) Auditing and Attestation (AUD) — Core syllabus — 5 chapters and 33 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.