CPA Auditing and Attestation: risk, evidence, and opinion

Auditing and Attestation (AUD) is one of the 3 mandatory Core sections — how auditors plan an engagement, gather evidence, and decide what opinion to issue. Here's the full breakdown, plus a worked audit risk model example.

Practice fresh AUD questions daily

No credit card required · FSRS scheduling · AI tutor included
Get started →

What CPA Auditing and Attestation actually tests

AUD is a Core section (required for every candidate):

AreaWhat it covers
Ethics & IndependenceAICPA Code of Professional Conduct, independence threats and safeguards
Audit PlanningRisk assessment (AU-C 315), materiality, analytical procedures
Internal ControlCOSO framework, ICFR assessment, significant deficiency vs. material weakness
Audit Evidence & SamplingSufficiency and appropriateness, attribute and variables sampling
Specific Accounts & Group AuditsRevenue, inventory, PP&E; using work of specialists
Fraud & Going ConcernAU-C 240 fraud, AU-C 570 going concern, subsequent events
Audit ReportsUnmodified, modified opinions; PCAOB standards for public companies
Attestation & Other EngagementsSSAE 18, SSARS reviews, compilations, governmental auditing (GAGAS)

Why the audit risk model is worth internalizing as a formula, not just a concept

AUD tests the audit risk model both conceptually and computationally — given any two of inherent, control, and detection risk (plus the desired overall audit risk), you should be able to solve for the missing piece. It's one of the few genuinely formulaic relationships in an otherwise heavily conceptual section.

Sample question: Audit Risk Model

Auditing and Attestation · Medium difficulty

Inherent risk is assessed at 80%, control risk at 50%, and the auditor wants overall audit risk to be no more than 5%. Using the audit risk model, what is the maximum acceptable level of detection risk?

A. 5%
B. 8%
C. 12.5%
D. 20%
The correct answer is C — 12.5%.
Audit Risk = Inherent Risk × Control Risk × Detection Risk, so Detection Risk = AR / (IR × CR) = 0.05 / (0.80 × 0.50) = 0.05 / 0.40 = 12.5%. The higher the combined inherent and control risk, the lower the acceptable detection risk — meaning more substantive testing is required to reach the same overall audit risk target.

Master AUD with adaptive practice

Fresh audit risk and evidence questions daily · Full explanations · No card needed
Get started →

More CPA sections