What CPA Auditing and Attestation actually tests
AUD is a Core section (required for every candidate):
| Area | What it covers |
|---|---|
| Ethics & Independence | AICPA Code of Professional Conduct, independence threats and safeguards |
| Audit Planning | Risk assessment (AU-C 315), materiality, analytical procedures |
| Internal Control | COSO framework, ICFR assessment, significant deficiency vs. material weakness |
| Audit Evidence & Sampling | Sufficiency and appropriateness, attribute and variables sampling |
| Specific Accounts & Group Audits | Revenue, inventory, PP&E; using work of specialists |
| Fraud & Going Concern | AU-C 240 fraud, AU-C 570 going concern, subsequent events |
| Audit Reports | Unmodified, modified opinions; PCAOB standards for public companies |
| Attestation & Other Engagements | SSAE 18, SSARS reviews, compilations, governmental auditing (GAGAS) |
Why the audit risk model is worth internalizing as a formula, not just a concept
AUD tests the audit risk model both conceptually and computationally — given any two of inherent, control, and detection risk (plus the desired overall audit risk), you should be able to solve for the missing piece. It's one of the few genuinely formulaic relationships in an otherwise heavily conceptual section.
Sample question: Audit Risk Model
Inherent risk is assessed at 80%, control risk at 50%, and the auditor wants overall audit risk to be no more than 5%. Using the audit risk model, what is the maximum acceptable level of detection risk?
Audit Risk = Inherent Risk × Control Risk × Detection Risk, so Detection Risk = AR / (IR × CR) = 0.05 / (0.80 × 0.50) = 0.05 / 0.40 = 12.5%. The higher the combined inherent and control risk, the lower the acceptable detection risk — meaning more substantive testing is required to reach the same overall audit risk target.