16 Auditing & Attestation (AUD) Practice Questions & Answers
Every Auditing & Attestation (AUD) practice question from the CPA Exam Practice Test, with the correct answer and a short explanation.
Start practice test →1. In the audit risk model, audit risk is a function of inherent risk, control risk, and detection risk. If the auditor assesses the combined inherent and control risk (the risk of material misstatement) as high, what should happen to the acceptable level of detection risk to keep audit risk low?
- A.It must be increased, allowing less substantive testing
- B.It must be decreased, requiring more persuasive substantive evidence✓ Answer
- C.It must be set to zero to eliminate audit risk entirely
- D.It is unaffected because detection risk is set independently
Detection risk has an inverse relationship with the risk of material misstatement. When inherent and control risk are high, the auditor must lower the acceptable detection risk by performing more extensive or effective substantive procedures so that overall audit risk stays acceptably low.
Source: AU-C 200.14 and .A44 (audit risk model; detection risk inverse relationship)Report a problem with this question
2. Professional skepticism, as required throughout an audit, is best described as:
- A.A requirement to obtain absolute assurance that the financial statements are free of error
- B.An assumption that management is dishonest until proven otherwise
- C.A duty owed only when fraud has already been identified
- D.An attitude that includes a questioning mind and a critical assessment of audit evidence✓ Answer
Professional skepticism is an attitude combining a questioning mind and a critical assessment of evidence. It does not presume management dishonesty (nor unquestioned honesty), and an audit provides reasonable—not absolute—assurance, so the skeptical mindset applies throughout, not only after fraud is found.
Source: AU-C 200.13(l) and .A22 (definition of professional skepticism)Report a problem with this question
3. Under the AICPA Code of Professional Conduct, independence is required for which type of engagement?
- A.A bookkeeping engagement with no attest report
- B.A tax return preparation engagement
- C.A financial statement audit (an attest engagement)✓ Answer
- D.A management consulting engagement
Independence in fact and appearance is required only for attest engagements, such as audits and reviews. Non-attest services like tax preparation, consulting, or bookkeeping require objectivity and integrity but not independence, because no assurance report is issued.
Source: AICPA Code of Professional Conduct ET 1.200 (Independence Rule; applies to attest engagements)Report a problem with this question
4. Which of the following is NOT one of the five components of the COSO Internal Control—Integrated Framework?
- A.Control environment
- B.Risk assessment
- C.Monitoring activities
- D.Detection risk✓ Answer
The five COSO components are the control environment, risk assessment, control activities, information and communication, and monitoring activities. Detection risk is a component of the audit risk model, not of internal control.
Source: COSO Internal Control—Integrated Framework (2013), five componentsReport a problem with this question
5. An auditor is unable to obtain sufficient appropriate audit evidence about a material and pervasive account, and cannot determine the possible effects on the financial statements. Which opinion is appropriate?
- A.Disclaimer of opinion✓ Answer
- B.Unmodified opinion
- C.Qualified opinion
- D.Adverse opinion
A disclaimer of opinion is issued when the auditor cannot obtain sufficient appropriate evidence (a scope limitation) and the possible effects are both material and pervasive, so the auditor cannot form an opinion. An adverse opinion, by contrast, results from a pervasive misstatement, not a scope limitation.
Source: AU-C 705.09–.10 (disclaimer for pervasive scope limitation)Report a problem with this question
6. A company's financial statements contain a departure from the applicable financial reporting framework that is material but NOT pervasive, and the departure is clearly quantified. Which opinion should the auditor express?
- A.Qualified opinion✓ Answer
- B.Adverse opinion
- C.Disclaimer of opinion
- D.Unmodified opinion
A qualified 'except for' opinion is appropriate when a misstatement is material but not pervasive. Because the effect is isolated rather than affecting the statements as a whole, the auditor qualifies the opinion rather than rendering an adverse opinion (which requires pervasiveness).
Source: AU-C 705.07–.08 (qualified opinion for material, non-pervasive misstatement)Report a problem with this question
7. Which of the following types of audit evidence is generally considered the MOST reliable?
- A.Inquiry of the client's accounting staff
- B.Confirmations received directly from independent third parties✓ Answer
- C.Copies of vendor invoices held in the client's files
- D.A written representation letter from management
Evidence obtained directly by the auditor from knowledgeable, independent external sources is more reliable than evidence generated internally or provided by management. Third-party confirmations received directly by the auditor rank highest among these options for that reason.
Source: AU-C 500.A31–.A34 (reliability of audit evidence hierarchy)Report a problem with this question
8. Materiality in an audit is best described as:
- A.A threshold that applies only to the balance sheet
- B.A fixed percentage of net income set by auditing standards
- C.The magnitude of an omission or misstatement that could influence the decisions of financial statement users✓ Answer
- D.The maximum dollar amount of fraud an auditor will tolerate
Materiality is judged by whether a misstatement or omission, individually or in aggregate, could reasonably be expected to influence the economic decisions of users. Standards provide no single fixed percentage; it requires professional judgment and applies to the statements as a whole.
Source: AU-C 320.02 and .04 (materiality based on users' decisions)Report a problem with this question
9. What is the primary distinction, in terms of the level of assurance provided, between an audit, a review, and a compilation of financial statements?
- A.A review gives absolute assurance while an audit gives only reasonable assurance
- B.All three provide reasonable assurance, differing only in fee
- C.An audit gives reasonable assurance, a review gives limited assurance, and a compilation provides no assurance✓ Answer
- D.A compilation gives the highest assurance because the CPA prepares the statements
An audit provides reasonable (high, but not absolute) assurance and expresses an opinion; a review provides limited (moderate, negative) assurance based mainly on inquiry and analytical procedures; a compilation provides no assurance because the CPA merely assists in presenting information without testing it.
Source: AR-C 60/70/80 and AU-C 200 (assurance levels: audit, review, compilation)Report a problem with this question
10. An auditor decides to inspect only a subset of the items in a large population and to project the results to the whole population. This approach is known as:
- A.A 100% examination
- B.Reperformance
- C.Audit sampling✓ Answer
- D.Analytical review
Audit sampling is the application of procedures to less than 100% of a population such that each item has a chance of selection, allowing the auditor to draw a conclusion about the entire population. Sampling introduces sampling risk—the risk the sample is not representative.
Source: AU-C 530.05 (definition of audit sampling and sampling risk)Report a problem with this question
11. The overall objectives of the independent auditor in a financial statement audit are to obtain reasonable assurance about whether the statements are free of material misstatement and to:
- A.Guarantee the future viability of the entity
- B.Report on the financial statements and communicate as the standards require✓ Answer
- C.Detect every error and fraud regardless of amount
- D.Prepare the financial statements on behalf of management
The auditor's overall objectives are to obtain reasonable assurance that the statements are free of material misstatement and to report on them (and communicate) in accordance with the standards. An audit does not guarantee the entity's future, detect all misstatements, or involve preparing the statements.
Source: AU-C 200.12 (overall objectives of the independent auditor)Report a problem with this question
12. Which statement about inherent risk and control risk is correct?
- A.They exist independently of the audit and together make up the risk of material misstatement✓ Answer
- B.They are set by the auditor and can be controlled by changing audit procedures
- C.They apply only to public companies
- D.They are the same as detection risk
Inherent risk and control risk are the entity's own risks—they exist regardless of the audit and together form the risk of material misstatement, which the auditor assesses but does not control. Only detection risk is influenced by the nature, timing, and extent of the auditor's procedures.
Source: AU-C 200.13(n) and .A44 (risk of material misstatement = inherent × control risk)Report a problem with this question
13. An auditor recalculates the client's depreciation expense independently and traces amounts to the general ledger. This substantive procedure is an example of:
- A.Confirmation
- B.Reperformance/recalculation✓ Answer
- C.Inquiry
- D.Observation
Recalculating a figure and independently checking its mathematical accuracy is reperformance/recalculation. Because the auditor personally performs the computation, this evidence is highly reliable, unlike inquiry (verbal) or observation (a point in time).
Source: AU-C 500.A21 (recalculation and reperformance as audit procedures)Report a problem with this question
14. An auditor concludes that misstatements, individually or in aggregate, are both material AND pervasive to the financial statements. Which type of opinion should the auditor express?
- A.Unmodified (unqualified) opinion
- B.Adverse opinion✓ Answer
- C.Qualified opinion
- D.Disclaimer of opinion
Under AU-C 705, when misstatements are material AND pervasive, an adverse opinion is required because the effects are so significant that the financial statements as a whole are not fairly presented. A qualified opinion is used when misstatements are material but NOT pervasive. Pervasiveness (not just materiality) is the trigger that distinguishes adverse from qualified.
Source: AU-C 705.08–.09 (Modifications to the Opinion in the Independent Auditor's Report)Report a problem with this question
15. To test the completeness assertion for accounts payable (i.e., to detect unrecorded liabilities), in which direction should the auditor perform the testing?
- A.From the trial balance to the confirmations returned by vendors
- B.From the recorded payables in the ledger to supporting vendor invoices
- C.From source documents (e.g., receiving reports, vendor invoices) to the accounting records✓ Answer
- D.From the general ledger balance to the financial statements
Completeness concerns understatement — the risk that liabilities exist but were not recorded. To detect this, the auditor traces FROM source documents (receiving reports, unpaid vendor invoices) INTO the accounting records to see if each transaction was captured. Testing the opposite direction (from the ledger to documents) tests existence/occurrence, not completeness.
Source: AU-C 315 / AU-C 500 (relevant assertions; direction of testing for completeness vs. existence)Report a problem with this question
16. Which statement best describes 'professional skepticism' as required throughout an audit?
- A.An assumption that management is dishonest and the records are fraudulent
- B.An attitude that includes a questioning mind and a critical assessment of audit evidence✓ Answer
- C.A requirement to obtain absolute assurance that the statements are free of misstatement
- D.Reliance on the honesty and integrity of management, taking records at face value
AU-C 200 defines professional skepticism as an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to error or fraud, and a critical assessment of audit evidence. It does NOT presume management dishonesty, nor does it permit unquestioning trust; it also does not require absolute assurance, since an audit provides only reasonable assurance.
Source: AU-C 200.14 and .A22 (Overall Objectives of the Independent Auditor)Report a problem with this question
Concept-focused practice questions based on the AICPA CPA Exam Blueprints. Not affiliated with the AICPA or NASBA, and not accounting, tax, or legal advice. Specific dollar thresholds change yearly — confirm current figures with authoritative sources. About the CPA Exam →