CPA Auditing and Attestation: risk, evidence, and opinion

Auditing and Attestation (AUD) is one of the 3 mandatory Core sections — how auditors plan an engagement, gather evidence, and decide what opinion to issue. Here's the full breakdown, plus a worked audit risk model example.

Find the gap you didn't know you had

10 questions · about 4 minutes · no account. It names the concept underneath your wrong answers, not just the topic.
Take the free CPA diagnostic →

Practice fresh AUD questions daily

FSRS scheduling · AI tutor included
Get started →

What CPA Auditing and Attestation actually tests

AUD is a Core section (required for every candidate):

AreaWhat it covers
Ethics & IndependenceAICPA Code of Professional Conduct, independence threats and safeguards
Audit PlanningRisk assessment (AU-C 315), materiality, analytical procedures
Internal ControlCOSO framework, ICFR assessment, significant deficiency vs. material weakness
Audit Evidence & SamplingSufficiency and appropriateness, attribute and variables sampling
Specific Accounts & Group AuditsRevenue, inventory, PP&E; using work of specialists
Fraud & Going ConcernAU-C 240 fraud, AU-C 570 going concern, subsequent events
Audit ReportsUnmodified, modified opinions; PCAOB standards for public companies
Attestation & Other EngagementsSSAE 18, SSARS reviews, compilations, governmental auditing (GAGAS)

Why the audit risk model is worth internalizing as a formula, not just a concept

AUD tests the audit risk model both conceptually and computationally — given any two of inherent, control, and detection risk (plus the desired overall audit risk), you should be able to solve for the missing piece. It's one of the few genuinely formulaic relationships in an otherwise heavily conceptual section.

Sample question: Audit Risk Model

Auditing and Attestation · Medium difficulty

Inherent risk is assessed at 80%, control risk at 50%, and the auditor wants overall audit risk to be no more than 5%. Using the audit risk model, what is the maximum acceptable level of detection risk?

A. 5%
B. 8%
C. 12.5%
D. 20%
The correct answer is C — 12.5%.
Audit Risk = Inherent Risk × Control Risk × Detection Risk, so Detection Risk = AR / (IR × CR) = 0.05 / (0.80 × 0.50) = 0.05 / 0.40 = 12.5%. The higher the combined inherent and control risk, the lower the acceptable detection risk — meaning more substantive testing is required to reach the same overall audit risk target.

The AUD blueprint, area by area

Pinnacle runs on a syllabus graph — named areas with explicit prerequisites, each one mapped against the AICPA's Uniform CPA Examination Blueprints effective January 2026. It is the same map the free diagnostic reasons over, not a marketing summary of it. These are the six confirmed AUD areas, and what each one covers:

Ethics, Independence & Professional Responsibilities

The AICPA Code of Professional Conduct and its conceptual frameworks, SEC and PCAOB independence requirements for issuer audits, GAO and Department of Labor requirements, and professional skepticism — including the unconscious biases, threats, incentives and judgment shortcuts that undermine it. Also here: the nature and scope of audit, attestation and review engagements, terms of engagement, documentation requirements, communications with management and those charged with governance, and engagement quality under the quality management standards.

Assessing Risk & Planning

Building the engagement strategy and plan; understanding the entity and its environment, including Sarbanes-Oxley governance provisions; setting materiality, tolerable misstatement and performance materiality; and assessing and responding to risks of material misstatement — fraud pressures, incentives and opportunities included — at the statement and assertion level. Specific engagement risks get their own tasks: compliance with laws and regulations, accounting estimates, related parties, and Uniform Guidance single audits.

Internal Control & ICFR

The COSO Internal Control-Integrated Framework applied to the control environment, business processes and IT — entity-level controls, IT general controls, service organizations — plus the limitations of controls and the risk of management override. Evaluating identified deficiencies as significant deficiencies or material weaknesses, communicating them, and auditing internal control over financial reporting in an integrated audit.

Performing Procedures & Obtaining Evidence

Obtaining sufficient appropriate evidence: data reliability and analytics with automated tools, sampling, tests of controls and tests of details, substantive analytical procedures, and external confirmations with their exceptions and nonresponses. Special-consideration matters — estimates, fair value of securities, inventory, litigation, going concern, federal awards testing — plus misstatement evaluation, written representations, and subsequent events.

Forming Conclusions & Reporting

Forming the opinion and writing the report: unqualified through adverse and disclaimer opinions for issuers and nonissuers, emphasis-of-matter and other-matter paragraphs, and separate or combined reports on internal control. Other reporting: comparatives and consistency, other information alongside audited statements, interim reviews, supplementary information, Government Auditing Standards requirements, and special-purpose frameworks such as the cash basis.

Other Engagements

Attestation engagements — assertion-based examinations, direct examinations, reviews, and agreed-upon procedures — and the SSARS engagements: preparation, compilation and review, with the factors an accountant considers and the form and content of the report for each.

Every practice question in the bank is tagged to one of these blueprint areas — which is how the diagnostic can name the specific concept underneath a wrong answer, not just the area it sat in.

Area names follow the AICPA's published Uniform CPA Examination Blueprints (effective January 2026), referenced for accuracy. Pinnacle is an independent adaptive learning platform. CPA is a professional designation administered by US state boards of accountancy. Pinnacle is not affiliated with, endorsed by, or connected to the AICPA, NASBA, or any US state board of accountancy.

Master AUD with adaptive practice

Fresh audit risk and evidence questions daily · Full explanations
Get started →

More CPA sections