Ethics & the Audit Process

Medium

Find each AUD term hidden in the grid. Selecting a word reveals its definition and a link to study it in depth.

9 terms · Choose how you want to study

New to the CPA Exam (Core Sections) exam? Read our how-to-pass guide →

Study modes

Terms in this set

Professional Skepticism

An attitude of questioning mind and critical assessment of audit evidence throughout the engagement.

AUD tests this with a scenario where management gives a plausible-sounding explanation and asks what a skeptical auditor does. The credited answer almost always corroborates the explanation with independent evidence rather than accepting it because management has “always been honest” or because controls looked fine last year. Watch for the tell of contradictory or inconsistent evidence (a confirmation that disagrees with the ledger, an unusual related-party transaction): skepticism means investigate the discrepancy, never explain it away. AU-C 200 requires this mindset throughout the engagement, and AU-C 240 makes it particularly important for fraud risk — you maintain skepticism notwithstanding any prior experience of management’s honesty.

The classic trap is confusing skepticism (a state of mind) with independence (freedom from impairing relationships) or with audit evidence (the information examined) — you can be perfectly independent yet insufficiently skeptical. Skepticism is neutral: you neither assume guilt nor presume honesty. Memory hook: skepticism is the verb, evidence is the noun — the attitude that drives you to gather and challenge proof.

Auditor Independence

The requirement that an auditor be free of relationships that impair, or appear to impair, objectivity.

AUD loves a “which threat / does this impair independence” stem: the answer hinges on the AICPA Conceptual Framework’s seven threats (self-review, advocacy, adverse-interest, familiarity, undue-influence, self-interest, management-participation) and whether a safeguard reduces the threat to an acceptable level. The classic trap is the covered member rule: a direct financial interest always impairs regardless of materiality, while an indirect interest impairs only if material (a diversified mutual fund that holds the client is usually indirect, immaterial unless you own >5% of the fund). Watch for bookkeeping or any management responsibility for an SEC issuer audit client — flatly prohibited under SEC/SOX rules, no safeguard cures it.

Don’t confuse independence with professional skepticism, a questioning mindset applied to evidence. Independence is required for audits and reviews (both attest), but not for compilations (impairment just gets disclosed) or for preparation/consulting engagements. The engagement letter documents terms but never “creates” independence. Memory hook: the reasonable, informed third-party test polices appearance even when your judgment is actually unaffected.

Engagement Letter

A written agreement establishing the terms, scope, and responsibilities of an audit engagement.

AUD item-writers love to test timing and who signs. The classic stem describes a document obtained, then asks which one it is, or what the auditor must establish before accepting the engagement. The tell: anything about the preconditions for an audit—management acknowledging its responsibility for the financial statements and internal control, and agreeing to provide access to information—points to the engagement letter (AU-C 210). It is the document signed by both the auditor and the client, obtained at the start.

The trap is confusing it with the management representation letter (AU-C 580): signed only by management, addressed to the auditor, and dated as of the audit report date—the very end (some banks frame this “first vs. last document”). Independence is a separate gate—a state to maintain, not an agreement to sign. Also remember: on recurring audits a new letter is not required annually unless terms or circumstances change, and a management-imposed scope limitation severe enough to force a disclaimer means the auditor should not accept the engagement rather than just note it.

Going Concern

The assumption that an entity will continue operating for a reasonable period of time.

AUD tests this as a chain of decisions: first identify conditions and events (recurring losses, negative working capital, loan default, denial of trade credit) raising substantial doubt, then weigh management’s plans to judge whether the doubt is alleviated. The “tell” is the look-forward window—under current US GAAP it runs one year from the date the statements are issued (or available to be issued), set by the applicable framework, not the balance-sheet date (older banks still teach the legacy “one year past the balance-sheet date”). If doubt remains but disclosure is adequate, add the dedicated “Substantial Doubt About the Entity’s Ability to Continue as a Going Concern” section even though the opinion stays unmodified.

The classic trap is confusing this with subsequent events: going-concern conditions often arise from post–year-end events, but they trigger a report section, not the recognized/nonrecognized split. Likewise, doubt alone never forces a qualified or adverse opinion—inadequate disclosure does, and refusal to disclose management’s plans (a pervasive scope limitation) points toward a disclaimer. Remember: doubt disclosed correctly = clean opinion plus a separate section.

Subsequent Events

Events occurring after the balance sheet date but before the date of the auditor's report that may require adjustment or disclosure.

AUD loves the two-type sort: given a fact (a lawsuit settles, a customer goes bankrupt, a fire destroys a plant), decide whether the underlying condition existed at the balance-sheet date. If it did, it’s a Type I (recognized) event and you adjust the numbers; if it arose only after, it’s Type II (nonrecognized) and you disclose. The classic trap: treating a post-date customer bankruptcy as Type II when the receivable was already impaired at year-end (Type I). Tested procedures include reading minutes, the latest interim statements, and inquiry of management and legal counsel (AU-C 560).

Don’t confuse the report date cutoff with later discoveries: a fact found after the report date can be handled by dual dating, not a redo of the whole audit. The management representation letter is dated as of the report date, so it covers the full subsequent-events window. Keep going concern separate — that’s a forward “substantial doubt” judgment over a reasonable period (about one year), not a backward adjust-or-disclose call.

Management Representation Letter

A letter from management confirming its responsibilities and key representations to the auditor.

AUD loves the consequence of refusal: if management won’t furnish requested written representations, that is a scope limitation (AU-C 580). For the required representations about management’s responsibilities, refusal forces a disclaimer or withdrawal — a qualified opinion is not appropriate — though for other refused reps, circumstances may still permit a qualified opinion. A second “tell” is the signers: those with overall responsibility, typically the CEO and CFO, never the auditor or engagement partner. And because reps are internally generated and self-serving (the weakest evidence), they can never substitute for procedures the auditor could otherwise perform.

Do not confuse this with the engagement letter: the client signs that at the start to fix scope and terms, while the rep letter comes from management at completion. Memory hook: “reps wrap up, engagement opens up.” Dated as of the report date, it spans the auditor’s subsequent-events responsibility window — and newer reps now cover uncorrected misstatements and management’s fraud-prevention/detection responsibility.

Attestation Engagement

An engagement in which a CPA reports on subject matter or an assertion that is the responsibility of another party.

AUD loves to test the three levels of assurance: an examination yields reasonable (positive) assurance, a review yields limited (negative) assurance, and an agreed-upon procedures (AOP) engagement yields no assurance—the practitioner only reports findings. The classic tell is a question describing a CPA reporting on non-financial-statement subject matter (greenhouse-gas data, a schedule of investment returns, MD&A), then asking which standards apply: the answer hinges on the SSAEs (AT-C sections), not the SASs (AU-C sections) that govern GAAS financial-statement audits.

The trap is conflating attestation with auditing. An audit is itself an attest service, but a financial-statement audit is performed under the SASs, while the SSAEs cover other attest subject matter. Distinct from both, SSARS governs compilations (AR-C 80) and preparations (AR-C 70)nonassurance services that are not SSAE attestation engagements. Don’t confuse a SSARS review (historical financials, AR-C 90) with an SSAE review (other subject matter, AT-C 210); AOP lives at AT-C 215. SOC 1/SOC 2 are examinations under the SSAEs. Hook: E-R-A—Exam, Review, AOP, high to zero assurance.

Review Engagement

An engagement providing limited assurance, primarily through inquiry and analytical procedures.

For a nonissuer, a review falls under SSARS (AR-C 90), performed by accountants in public practice; AUD tests whether you can rank the engagement hierarchy by effort and assurance: preparation < compilation < review < audit. The classic “tell” is a fact pattern stating the CPA performed inquiry and analytical procedures but did NOT confirm receivables, observe inventory, or test internal controls — the answer is a review, and the report expresses limited (negative) assurance that the CPA is “not aware of any material modifications” needed for GAAP conformity. Watch for the independence trap: independence is required for a review (unlike a compilation, where a CPA may lack independence but must disclose it).

Don’t confuse a SSARS review with a review under the attestation standards (SSAE/AT-C), which covers subject matter other than historical financials, or an interim review of an issuer under PCAOB AS 4105. A review yields no audit opinion and never expresses positive (reasonable) assurance. Memory hook: a review only R-eads and R-easons (inquiry plus analytics) — no verifying, vouching, or confirming.

SOC Reports

System and Organization Controls reports on a service organization's controls relevant to its clients.

AUD loves to make you choose the report number and the type. The “tell” is who reads it and why: a financial-statement auditor whose client outsourced payroll needs a SOC 1 (controls over financial reporting, examined under SSAE No. 18 / AT-C 320); a buyer evaluating a vendor’s security, availability, processing integrity, confidentiality, or privacy needs a SOC 2 (the five Trust Services Criteria, under AT-C 205). Marketing-grade, general-use distribution gets a SOC 3. Then nail Type 1 vs Type 2: Type 1 tests design at a point in time; Type 2 tests operating effectiveness over a period—that’s the answer when the user auditor wants reliance.

The classic trap is treating SOC like an opinion on the service organization’s financial statements—it isn’t; it reports on a service organization’s controls, the system the entity in internal control relies on. Don’t confuse the service auditor (writes the report) with the user auditor (relies on it), and know the carve-out vs inclusive method for subservice organizations. Hook: “1 = financials, 2 = security.”