← Home
Uniform CPA Examination · Core Section · CPA Evolution Blueprint (2026)

AUD — Auditing and Attestation

Pilot teaching module — built as the template for the full 4-section CPA course (AUD · FAR · REG · Discipline). Full notes across all four Blueprint Areas, worked examples you reveal one step at a time, six interactive audit-judgment tools, a tagged 178-question practice bank, a timed assessment with a published attainment report, and exam-pattern task-based-simulation (TBS) case prompts — all in one file.

Exam format 78 MCQs + 7 TBS · 4 hrs Pass score 75 Areas I · II · III · IV Skill levels R&U · Application · Analysis · Evaluation Bank

Core Section · Pilot module

From ethics and risk to evidence and the opinion you finally sign

AUD is the section that carries an accountant's judgment from principle into practice. Area I sets the professional and ethical foundation — independence, skepticism, quality management. Area II asks what could go wrong: understanding the entity, its controls, and the risks of material misstatement, and setting materiality. Area III — the largest area on the exam — is where the auditor actually gathers sufficient appropriate evidence in response to those risks: sampling, tests of controls, substantive procedures, estimates, confirmations, subsequent events. Area IV closes the loop: forming a conclusion and writing the report that says so, whether that report is an audit opinion, a review, a compilation, or an attestation.

How this module is organized

  • Read — all four Blueprint Areas, each broken into short sections, with definition tables, worked examples you step through, and concept checks.
  • Interactive tools — an audit risk model calculator, a materiality calculator, an opinion-type decision tool, an assurance-level identifier, a sampling evaluator, and a subsequent-events classifier.
  • Practice — a bank of 178 MCQs, filterable by Area, topic, Blueprint skill level, and difficulty.
  • Assessment — build a timed test from the bank and get a published attainment report by Area and by skill level (pass line: 75%, matching the real exam's scoring scale).
  • Case studies & readings — seven exam-pattern TBS-style scenario prompts, plus a further-reading list tied to the AICPA/PCAOB standards referenced throughout.

The four Blueprint Areas & their weight

AreaFocusWeight
IEthics, independence, quality management, legal/regulatory15–25%
IIUnderstanding the entity, internal control, risk assessment, materiality25–35%
IIIEvidence, sampling, tests of controls, substantive procedures30–40%
IVOpinions, attestation reports, SSARS, compliance reporting10–20%

AUD is the only CPA Exam section tested at the Evaluation skill level — the highest order, requiring a deduction, judgment, or decision from a full set of facts, not just recall or calculation.

How to use the worked examples

Read the scenario, form your own judgment first, then click Show next step to check your reasoning one line at a time rather than jumping straight to the conclusion — this mirrors how you'll actually need to reason through a TBS on exam day.

Area I · 15–25%

Ethics, Professional Responsibilities & General Principles

1 · Independence & the conceptual framework

Every AUD topic ultimately rests on a simple premise: the auditor's opinion is worth something only because the auditor is independent — both in fact (an actual unbiased state of mind) and in appearance (how a reasonable, informed third party would see it). The AICPA Code of Professional Conduct handles situations a specific rule doesn't clearly cover with a conceptual framework: identify the threat (self-interest, self-review, advocacy, familiarity, undue influence, management participation, adverse interest), evaluate its significance, and apply safeguards to eliminate it or reduce it to an acceptable level.

Threat categoryTypical trigger
Self-interestA financial or other personal interest in the client (e.g., direct stock ownership)
Self-reviewAuditing your own firm's prior nonattest work (e.g., bookkeeping you performed)
FamiliarityA close or long relationship with client management (e.g., long engagement tenure)
Management participationTaking on a management role or function for the client
Undue influencePressure from an aggressive or dominant client to reduce audit quality

For issuers, SEC and PCAOB independence rules are stricter and largely bright-line: any direct financial interest of a covered person impairs independence regardless of materiality, and a defined list of nonaudit services (bookkeeping, valuation, internal audit outsourcing, management functions, and others) is prohibited outright — no safeguard cures them.

Worked Example 1.1 · Application
Evaluating a nonattest-services independence threat

Facts: Your firm prepares the trial balance and posts adjusting entries for Riverton Co., a nonissuer, and your firm also audits Riverton's financial statements. Riverton's controller reviews and approves every entry before posting, understands the accounting treatment, and takes responsibility for the final numbers.

Step 1

Identify the threat: performing bookkeeping and then auditing the results of that bookkeeping creates a self-review threat — you'd be auditing your own work.

Step 2

Check the safeguard: independence is preserved for a nonissuer nonattest service only if the client accepts management responsibility — makes all significant judgments, understands the work performed, and evaluates its adequacy.

Step 3

Apply the facts: the controller reviews, understands, and takes responsibility for every entry — that satisfies the management-responsibility safeguard.

Conclusion: Independence is not impaired, provided this safeguard is genuinely operating (not just documented) and the firm also confirms no other threats (e.g., excessive fee dependence) exist.

Concept check — For an issuer audit client, which nonaudit service is prohibited outright, regardless of safeguards?

2 · Quality management & legal responsibility

SQMS No. 1 replaced the older, checklist-style quality control standard with a proactive, risk-based system of quality management: the firm sets quality objectives, identifies and assesses the risks that threaten those objectives, and designs responses scaled to its own size and complexity. At the individual engagement level, the engagement partner holds overall responsibility for quality, and on applicable engagements an engagement quality reviewer — someone outside the engagement team — objectively evaluates the significant judgments made before the report is released.

Auditors of government entities and programs work under an additional layer: Government Auditing Standards (the "Yellow Book") layers extra independence and CPE requirements onto AICPA/PCAOB standards, and a Single Audit under the Uniform Guidance is triggered once a non-federal entity's federal award expenditures cross the applicable threshold — producing not just a financial statement opinion but a separate opinion on compliance for each major program.

Legal liability, in one line

Ordinary negligence generally exposes the auditor to the client and, in many jurisdictions, to a limited "foreseen class" of third parties known to rely on the report — not to every conceivable unknown user.

Concept check — A Single Audit under the Uniform Guidance results in an opinion on —

Area II · 25–35%

Assessing Risk & Developing a Planned Response

3 · The audit risk model & materiality

The audit risk model is the spine of Area II: AR = IR × CR × DR. Inherent risk (IR) and control risk (CR) exist independent of the auditor — they describe the entity, not the audit. Detection risk (DR) is the one lever the auditor controls: given a target overall audit risk and the assessed IR and CR, the auditor solves for the maximum acceptable DR and designs procedures (nature, timing, extent) to keep actual detection risk at or below it. The higher the assessed risk of material misstatement (IR × CR), the lower DR must be — which means more persuasive, more extensive, more year-end-focused procedures.

Worked Example 2.1 · Application
Solving the audit risk model for detection risk

Facts: The auditor assesses inherent risk at 80% and control risk at 50% for the revenue cycle, and wants overall audit risk for that assertion to be no more than 5%.

Step 1

Write the model: AR = IR × CR × DR.

Step 2

Substitute the knowns: 0.05 = 0.80 × 0.50 × DR = 0.40 × DR.

Step 3

Solve: DR = 0.05 / 0.40 = 0.125, or 12.5%.

Conclusion: The auditor can accept at most a 12.5% risk that substantive procedures fail to detect a material misstatement, if one exists. That's a fairly low tolerance — procedures need to be reasonably extensive and reliable, not merely a light-touch review.

Materiality works alongside the risk model but answers a different question: how big does a misstatement have to be before it matters to a reasonable user? The auditor sets overall (planning) materiality from an appropriate benchmark (often income before tax for stable, profitable entities; revenue or total assets for others), then sets performance materiality below that — a deliberate buffer against the risk that several individually immaterial misstatements aggregate to something material.

BenchmarkBest suited to
Income before taxStable, profitable, for-profit entities where earnings drive user decisions
Total revenueEntities with volatile or near break-even earnings
Total assets / net assetsAsset-heavy entities, or not-for-profits with no earnings measure

Concept check — Performance materiality is set —

4 · Internal control (COSO) & fraud risk

The COSO framework's five components — control environment, risk assessment, control activities, information & communication, and monitoring activities — give the auditor a structure for understanding internal control, which feeds directly into the control-risk half of the audit risk model. A control deficiency that's important enough to merit governance's attention but doesn't rise to the level of a reasonable possibility of undetected material misstatement is a significant deficiency; one that does create that reasonable possibility is a material weakness.

Worked Example 2.2 · Evaluation
Classifying a deficiency: significant deficiency or material weakness?

Facts: The entity has no process for periodically reviewing user access to its financial reporting system. Several employees terminated months ago still have active login credentials. No compensating control exists.

Step 1

Identify what's missing: a basic IT general control — periodic access review — that underpins the reliability of every automated control and system-generated report downstream.

Step 2

Consider the population affected: this isn't a one-off error; it's a pervasive gap that could allow unauthorized transactions or data changes across the whole financial reporting system, for months at a time.

Step 3

Ask the test question: is there a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis? Given the scope and duration, yes.

Conclusion: This deficiency should be evaluated as a likely material weakness, absent a compensating control the auditor hasn't yet identified — and it must be communicated in writing to management and those charged with governance.

Standards require the auditor to presume, on every engagement, a risk of management override of controls and a risk of fraudulent revenue recognition — rebuttable, but never skipped. The fraud triangle (incentive/pressure, opportunity, rationalization) is the lens for evaluating fraud risk factors identified during planning, typically surfaced in a required engagement-team brainstorming session focused specifically on susceptibility to fraud.

Concept check — The three legs of the fraud triangle are —

Area III · 30–40%

Performing Further Procedures & Obtaining Evidence

5 · Sufficient appropriate evidence & sampling

Sufficiency is about quantity; appropriateness is about quality — relevance and reliability together. Reliability follows a rough hierarchy: evidence the auditor obtains directly (observation, recalculation, reperformance) and evidence from independent external sources generally outranks evidence generated internally by the client, which in turn outranks uncorroborated oral inquiry alone.

Because testing 100% of most populations isn't practical, the auditor accepts sampling risk — the risk that a sample-based conclusion would differ from the conclusion of testing the whole population — while trying to eliminate nonsampling risk (auditor error: the wrong procedure, a misread document) through careful, well-supervised work regardless of sample size.

Worked Example 3.1 · Evaluation
Deciding whether a variables-sampling result is conclusive

Facts: The auditor tests an account balance using variables sampling. Tolerable misstatement is $200,000. Projected misstatement combined with other known misstatements is $178,000. The achieved allowance for sampling risk (precision) is $90,000 — wide relative to the $22,000 cushion remaining.

Step 1

Compare projected misstatement to tolerable misstatement: $178,000 is below $200,000, so on its face the sample doesn't fail.

Step 2

But check precision: the achieved allowance for sampling risk ($90,000) is far wider than the remaining cushion ($22,000) — meaning the true population misstatement could plausibly sit anywhere in a $90,000 band around $178,000, which easily could exceed $200,000.

Step 3

Recognize the result is too close to call with confidence — accepting it at face value would understate sampling risk.

Conclusion: Treat the result as inconclusive. Extend the sample, perform alternative procedures, or request an adjustment — don't simply accept the balance because the point estimate happened to land under the line.

Concept check — Which is generally the LEAST reliable form of audit evidence on its own?

6 · Substantive procedures & special matters

Substantive procedures split into two families: analytical procedures, most powerful where a stable, predictable relationship among data is expected (payroll expense vs. headcount, interest expense vs. average debt), and tests of details, which trace specific items — vouching (recorded item → source document) toward occurrence, and tracing (source document → records) toward completeness. A few areas get special treatment because they're inherently higher-risk or judgment-heavy: accounting estimates (procedures scaled to estimation uncertainty and possible management bias), written representations (necessary but never sufficient on their own), and subsequent events.

TypeDefinitionFinancial statement effect
Type I (recognized)Provides evidence about conditions that existed at the balance sheet dateAdjust the financial statements
Type II (nonrecognized)Arises from conditions that did not exist at the balance sheet dateDisclose only (no adjustment)
Worked Example 3.2 · Analysis
Classifying a subsequent event

Facts: The entity's fiscal year ends December 31. On February 10, a major customer that had been struggling financially throughout the prior fall files for bankruptcy. The receivable from that customer was still on the books at $340,000 as of December 31, uncollected but not yet reserved.

Step 1

Ask when the underlying condition arose: the customer's financial deterioration was already underway before year-end — the bankruptcy filing in February is new information about a condition that existed at December 31, not a brand-new condition.

Step 2

Apply the definition: this matches Type I — evidence about a condition that existed at the balance sheet date.

Conclusion: The receivable should be adjusted (an allowance recorded) in the December 31 financial statements, not merely disclosed — contrast this with, say, a factory fire in February, which would be Type II (disclosure only), because the fire is a new condition that didn't exist at year-end.

Concept check — Vouching a recorded sale back to a shipping document primarily tests —

Area IV · 10–20%

Forming Conclusions & Reporting

7 · Audit report modifications

Every modified-opinion decision comes down to two questions: is the matter material, and if so, is it pervasive? The matrix below is the single most tested table in Area IV.

Nature of matterMaterial but not pervasiveMaterial AND pervasive
GAAP departure / misstatementQualified opinionAdverse opinion
Scope limitation (can't get sufficient evidence)Qualified opinionDisclaimer of opinion
Worked Example 4.1 · Evaluation
Choosing the opinion type

Facts: Management restricted the auditor's access to a foreign subsidiary representing 40% of consolidated assets, and no alternative procedures were possible. The auditor cannot conclude whether undetected misstatements related to that subsidiary could be material.

Step 1

Classify the matter: this is a scope limitation — the auditor could not obtain sufficient appropriate evidence — not a known GAAP departure.

Step 2

Judge materiality and pervasiveness: 40% of consolidated assets is both material and, because it touches a broad swath of the financial statements rather than one isolated line item, pervasive.

Step 3

Apply the matrix: scope limitation + material and pervasive → bottom-right cell.

Conclusion: A disclaimer of opinion is appropriate — the auditor does not express an opinion at all, because the possible undetected effects could be both material and pervasive.

Going concern doubt that's adequately disclosed, with no other issue, doesn't move the opinion off unmodified — it adds a required emphasis paragraph describing the substantial doubt. Confusing "modify the opinion" with "add an emphasis paragraph" is one of the most common Area IV mistakes.

Concept check — A material, but NOT pervasive, GAAP departure calls for a —

8 · Other engagements: attestation & SSARS

Not every engagement is an audit, and each level of service provides a different, precisely worded level of assurance:

EngagementAssurance levelReport form
Audit / ExaminationReasonable assurancePositive opinion
ReviewLimited assuranceNegative assurance ("nothing came to our attention...")
Agreed-Upon ProceduresNo overall assuranceFindings only — no opinion or conclusion
Compilation (SSARS)No assuranceCompilation report; no opinion
Preparation (SSARS)No assuranceNo report — a legend on the statements instead

SSARS engagements (compilation, review, preparation) apply to nonissuers' financial statements when the accountant is not engaged to audit. Even a compilation — which conveys no assurance — obligates the accountant to act if the statements appear materially misleading: request revision, and consider withdrawing if management refuses.

Concept check — Which engagement type expresses limited assurance in negative form?

Six audit-judgment tools

Interactive tools

These mirror the kind of judgment TBS prompts test — plug in facts, see the reasoning, not just a final number.

1 · Audit risk model calculator

Enter assessed inherent risk, control risk, and target overall audit risk. The tool solves AR = IR × CR × DR for the maximum acceptable detection risk.

2 · Materiality calculator

Pick a benchmark, enter its value and a rate within the typical range, and set a performance-materiality percentage.

3 · Opinion-type decision tool

Answer three questions about the matter identified and the tool applies the materiality/pervasiveness matrix.

4 · Assurance-level identifier

Pick an engagement type to see its assurance level, typical procedures, and report form side by side.

5 · Attribute-sampling evaluator (tests of controls)

Enter the sample size, deviations found, and tolerable deviation rate. The tool computes the sample deviation rate and compares it to the tolerable rate.

6 · Subsequent-events classifier

Answer whether the underlying condition existed at the balance sheet date, and whether the event was discovered before or after the report date, to see the classification and required action.

Filterable bank ·

Practice questions

Timed · exam pattern

Assessment

Build a timed test drawn from the practice bank, then get a published attainment report broken down by Area and by Blueprint skill level (target line: 75% — the CPA Exam's actual passing score).

Set up your test

Exam-pattern TBS prompts

Case studies (task-based simulation style)


Prescribed & further reading