CPA Exam — AUD flashcards
173 free flashcards. Tap a card to flip it.
Control Risk (Specialized Knowledge)
Flip cardControl risk can be high when personnel lack the necessary expertise to properly execute controls or account for complex transactions, leading to potential misstatements.
- Complex areas (e.g., derivatives, estimates) require specialized knowledge.
- Inadequate training or experience can weaken controls.
- Directly impacts assertions like valuation and allocation.
Memory trick: No 'VALUATION' expertise means 'CONTROL' risk is high.
Control Risk (Complex Transactions)
Flip cardControl risk is the risk that a material misstatement will not be prevented or detected by the entity's internal controls on a timely basis.
- High turnover or understaffing weakens controls.
- Complex, non-routine transactions are harder to control.
- Business combinations involve significant judgment and specialized accounting.
Memory trick: Turnover makes 'B'usiness 'C'ombinations a 'CONTROL' mess.
Valuation and Allocation Assertion
Flip cardThe valuation and allocation assertion states that assets, liabilities, and equity interests are included in the financial statements at appropriate amounts and any resulting valuation or allocation adjustments are appropriately recorded.
- Concerns the monetary amounts of financial statement elements.
- Relevant for estimates, complex calculations, and specific accounting principles.
- Ensures items are recorded at their proper value and assigned to the correct accounts/periods.
Memory trick: V-A: Value correctly, Allocate precisely.
Inherent Risk (Non-Routine Transactions)
Flip cardNon-routine transactions are inherently riskier due to their complexity, infrequency, and the greater judgment and specialized accounting knowledge often required.
- Often lack established, automated controls.
- Require significant management judgment and estimation.
- May involve new or unusual accounting principles.
Memory trick: Non-routine means 'COMPLEX' and 'RISKY'.
Walkthroughs
Flip cardA procedure in which the auditor traces a transaction from its origination through the entity's information system until it is reflected in the financial reports, including relevant controls.
- Provides understanding of transaction flow.
- Confirms understanding of internal controls.
- Helps identify control design deficiencies.
Memory trick: New systems, new risks? Walk through them!
Performance Materiality
Flip cardThe amount or amounts set by the auditor at less than materiality for the financial statements as a whole to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds materiality for the financial statements as a whole.
- Used for planning and performing audit procedures.
- Typically 50-75% of overall materiality.
- Lower when risk of material misstatement is higher.
Memory trick: High risk? Lower the bar for what's material to catch more!
Audit Risk Model - Inverse Relationship
Flip cardThe audit risk model demonstrates an inverse relationship between the auditor's assessed risks of material misstatement (Inherent Risk and Control Risk) and the acceptable level of Detection Risk. As assessed RMM increases, acceptable Detection Risk decreases.
- AR = IR x CR x DR.
- IR and CR are client-side risks.
- DR is auditor-controlled.
Memory trick: Higher client risk? Lower auditor risk action!
Control Risk - Automated Systems
Flip cardThe risk that a misstatement will not be prevented or detected by the entity's internal control system, specifically when controls are highly automated. Automated controls, if effective, can be very consistent.
- Reliance on automated controls requires testing their effectiveness.
- General IT controls (GITC) are crucial for the reliability of automated application controls.
- If controls are strong, control risk can be assessed lower, impacting detection risk.
Memory trick: Robots Rule, If Rules Are Set.
Fraud Risk - Analytical Procedures
Flip cardAnalytical procedures involve evaluating financial information by studying plausible relationships among financial and nonfinancial data. When performed during risk assessment, they are effective tools for identifying unusual trends or relationships that may indicate fraud risks, particularly in revenue recognition.
- Compare current data to expectations (prior periods, industry, budgets).
- Highlight unusual fluctuations or relationships.
- Require a thorough understanding of the business to interpret results.
Memory trick: Fraud risk often hides in 'unusual patterns'.
Control Environment & Competence
Flip cardThe control environment sets the tone of an organization, influencing the control consciousness of its people. A key component is management's commitment to competence, ensuring employees have the necessary knowledge and skills.
- Foundation for all other internal control components.
- Includes integrity, ethical values, management philosophy, and commitment to competence.
- Weaknesses can lead to pervasive risks.
Memory trick: Control Environment is the 'tone at the top' and the 'foundation'.
SOC 1 Report
Flip cardA Service Organization Control (SOC) 1 report provides user entities and their auditors with information about the controls at a service organization that are relevant to a user entity's internal control over financial reporting.
- Type 1 reports describe controls at a point in time.
- Type 2 reports describe controls over a period and include tests of operating effectiveness.
- Helps the user auditor understand and assess control risk related to outsourced functions.
Memory trick: Outsourced payroll? Get a 'SOC 1' to 'CHECK' their controls.
Owner-Manager Review as a Control
Flip cardIn small entities, active involvement and review by an owner-manager can serve as an effective compensating control, potentially reducing control risk despite limited segregation of duties.
- Can mitigate risks from lack of formal controls.
- Requires the owner-manager to be competent and diligent.
- Often seen in smaller, less complex organizations.
Memory trick: The Boss's Eye Catches the Flaws.
Significant Risk - Estimates
Flip cardSignificant risks are risks of material misstatement that are identified and assessed and, in the auditor's judgment, require special audit consideration. Significant accounting estimates are often considered significant risks due to their inherent subjectivity and complexity.
- Involve high degree of management judgment.
- Based on future events, inherently uncertain.
- Often require specialized knowledge to audit.
Memory trick: Significant Risks often stem from 'Subjective Judgments'.
Analytical Procedures - Inventory Turnover
Flip cardAnalytical procedures involve evaluating financial information by studying plausible relationships among both financial and non-financial data. Inventory turnover (COGS/Avg. Inventory) indicates how many times inventory is sold and replenished in a period.
- Unexpected fluctuations require investigation.
- Can signal over/understatement of inventory or COGS.
- Must consider related accounts (sales, purchases) for context.
Memory trick: Fast Inventory, Flat Sales, Something's Missing.
Fraud Triangle - Opportunity
Flip cardOpportunity refers to the circumstances that allow fraud to occur. It typically arises from weak internal controls, ineffective oversight, or the ability to override controls.
- Weak or absent internal controls create opportunity.
- Management's ability to override controls is a significant opportunity.
- Complex or unusual transactions can create hidden opportunities.
Memory trick: I Oughta Rationalize.
COSO Internal Control - Risk Assessment
Flip cardThe component of internal control that involves the entity's identification and analysis of relevant risks to the achievement of its objectives, forming a basis for determining how risks should be managed.
- Identifies and analyzes risks to achieving objectives.
- Considers internal and external factors.
- Forms basis for managing risks.
Memory trick: CRIME: Control Environment, Risk Assessment, Information, Monitoring, Existing Controls.
Control Risk & System Implementation
Flip cardControl risk is the risk that a material misstatement that could occur in an assertion will not be prevented or detected on a timely basis by the entity's internal control. Poor system implementation and inadequate training significantly elevate control risk.
- Weak controls increase likelihood of undetected misstatements.
- New systems require careful implementation and training.
- Control risk is assessed by the auditor.
Memory trick: Rushed systems mean 'control' goes out the window.
Control Risk - System Implementation
Flip cardThe risk that a material misstatement will not be prevented or detected on a timely basis by the entity's internal controls due to weaknesses arising from the implementation of new or significantly changed IT systems.
- New systems introduce unique risks (e.g., data conversion, interface errors).
- Focus on controls over data integrity and system configuration.
- User access and change management controls are critical.
Memory trick: New System, New Access, New Data Flow.
Inherent Risk - Non-Routine Transactions
Flip cardNon-routine transactions are those that occur only occasionally or are outside the normal course of business. They often involve significant management judgment and calculation, increasing their susceptibility to material misstatement.
- Often involve complex accounting principles.
- Less subject to established, routine internal controls.
- Require significant management judgment and estimation.
Memory trick: Unusual and Tricky = High Risk.
Inherent Risk Factors (Complexity)
Flip cardInherent risk is higher for transactions, accounts, or disclosures that are complex, involve significant judgment, or are subject to external factors.
- Complex calculations or accounting principles increase inherent risk.
- Estimates and subjective judgments are prone to higher inherent risk.
- New business models or unusual transactions often carry higher inherent risk.
Memory trick: Inherent risk is 'C'omplex, 'U'nusual, or 'E'stimates.
Significant Risk - Restricted Grants
Flip cardRestricted government grants introduce significant risk due to specific conditions, compliance requirements, and complex accounting rules, particularly affecting the proper presentation and disclosure in financial statements.
- Compliance with grant terms is critical.
- Often requires specific presentation in financial statements (e.g., net assets with donor restrictions).
- Risk of misclassification or inadequate disclosure is high.
Memory trick: Rules for Funds Mean Reporting Fails.
Control Risk Assessment - Acquisitions
Flip cardWhen auditing an acquired entity, especially one with inexperienced personnel or integration challenges, auditors should initially assess control risk as high unless evidence suggests otherwise, due to the inherent difficulties in establishing and maintaining effective ICFR in such circumstances.
- Acquisitions introduce new ICFR challenges.
- Inexperienced personnel increase control risk.
- High control risk dictates more substantive approach.
Memory trick: New company, new people? Assume controls are a mess!
Significant Risk (Fraud & Revenue)
Flip cardSignificant risks often involve complex transactions, high management judgment, and areas susceptible to fraud, especially when management incentives align with misstatement.
- Revenue recognition is presumed to be a significant risk.
- Management override of controls is a common fraud risk.
- New accounting standards increase complexity and judgment.
Memory trick: New 'REVENUE' rules + 'TARGETS' = 'OCCURRENCE' fraud risk.
COSO - Control Activities (Override)
Flip cardControl activities are policies and procedures that help ensure management directives are carried out. Management override of these controls indicates a significant weakness in this component.
- Includes authorizations, reconciliations, segregation of duties.
- Overrides bypass the intended purpose of controls.
- Frequent overrides can suggest a weak control environment as well.
Memory trick: Override of 'CONTROLS' means 'ACTIVITIES' are failing.
Service Organization Controls
Flip cardWhen an entity uses a service organization (e.g., for IT, payroll), the auditor must consider the impact of the service organization's controls on the user entity's internal controls over financial reporting.
- Auditor must obtain an understanding of the service organization's controls.
- This understanding is crucial for assessing control risk at the user entity.
- Often obtained through a SOC 1 report (Service Organization Control report).
Memory trick: Outsourced IT means your controls are 'SOC'ked up if you don't check them.
Control Environment - Management's Philosophy
Flip cardA component of the control environment, reflecting management's attitudes and actions toward financial reporting, risk-taking, and internal control, which sets the 'tone at the top' of the organization.
- Sets 'tone at the top'.
- Includes risk appetite and ethical values.
- Impacts effectiveness of other control components.
Memory trick: ICE CREAM: Integrity, Commitment, Ethics, Control, Risk, Environment, Authority, Management.
Segregation of Duties
Flip cardSegregation of duties is a fundamental internal control principle that assigns different responsibilities (authorization, record-keeping, custody, reconciliation) to different individuals to reduce the risk of errors and fraud.
- Prevents a single person from controlling an entire transaction.
- Reduces opportunity for fraud and concealment.
- Applies to all key business processes.
Memory trick: SOD: Split the Duties, Stop the Deception.
Inherent Risk & Estimates
Flip cardInherent risk is often higher for financial statement items that involve significant management judgment, complex calculations, or subjective estimates, as these factors increase the susceptibility to material misstatement.
- Estimates are inherently uncertain.
- Judgment can be subjective.
- Complexity increases chance of error.
Memory trick: Estimates are inherently 'guess-timates' with high risk.
Inherent Risk (System Implementation/Migration)
Flip cardNew system implementations or data migrations introduce inherent risks related to data integrity, completeness, and accuracy due to complexity and potential unforeseen issues.
- Data conversion/migration is a critical, error-prone step.
- Integration with other systems can be complex.
- Initial system setup and configuration can contain errors.
Memory trick: Cloud migration means 'DATA' 'INTEGRITY' is at 'RISK'.
Auditability
Flip cardAuditability refers to the extent to which an auditor can gather sufficient appropriate audit evidence to form an opinion on the fairness of a client's financial statements.
- Depends on the availability and reliability of accounting records and supporting documentation.
- Lack of auditability can lead to a disclaimer of opinion or withdrawal from the engagement.
- Strong internal controls generally improve auditability.
Memory trick: No Records, No Proof, No Audit.
Inherent Risk - Business Model Complexity
Flip cardThe susceptibility of financial statement assertions to material misstatement due to the inherent nature and complexity of the entity's business model, operations, or industry, before considering internal controls.
- Often higher in new or rapidly changing industries.
- Impacts revenue recognition, asset valuation, and intangible assets.
- Requires deep understanding of the client's operations.
Memory trick: New Tech, New Troubles, Rapid Change.
Inherent Risk
Flip cardThe susceptibility of an assertion about a class of transaction, account balance, or disclosure to a misstatement that could be material, either individually or when aggregated with other misstatements, before consideration of any related controls.
- Exists independently of the audit.
- Higher for complex transactions or estimates.
- Increased by industry factors, management characteristics, or business operations.
Memory trick: DR = IR x CR x DR (Detection = Inherent x Control x Detection)
Inherent Risk - Estimates
Flip cardThe susceptibility of an assertion to a material misstatement, before considering internal controls, due to the need for management estimates in financial reporting. Estimates inherently involve judgment and uncertainty.
- Increases with complexity and subjectivity of the estimate.
- Often impacts the 'Valuation and Allocation' assertion.
- Requires significant auditor judgment to assess reasonableness.
Memory trick: Estimates Always Test the True Value.
Inherent Risk (Restricted Grants)
Flip cardFor restricted grants, inherent risk is high due to the complexity and specific compliance requirements associated with their terms.
- Grants often come with specific spending and reporting conditions.
- Non-compliance can result in repayment or loss of future funding.
- Requires careful tracking and segregation of funds.
Memory trick: Restricted grants mean 'RULES' are 'RISKY'.
Auditor's Response to Significant Risks
Flip cardAuditors must design and implement overall responses to address assessed risks of material misstatement at the financial statement level, and design and perform specific audit procedures responsive to assessed risks at the assertion level.
- Responses should be proportionate to the risk.
- Responses can involve changes to the nature, timing, and extent of audit procedures.
- High risks often require more persuasive audit evidence.
Memory trick: Risk Calls for Direct Action and Evidence.
Entity-Level Controls
Flip cardEntity-level controls are controls that have a pervasive effect on the entity's internal control system as a whole. They are typically broader in scope and relate to the control environment, risk assessment, and monitoring activities.
- Operate at the company-wide level.
- Crucial for decentralized or complex organizations.
- Examples: tone at the top, management's risk assessment, internal audit.
Memory trick: Decentralized means you need strong 'entity' glue.
Entity-Level Controls (Decentralized)
Flip cardEntity-level controls are controls that operate across the entire entity and affect multiple processes and assertions. A decentralized structure can challenge their consistent application and effectiveness.
- Include controls related to the control environment, risk assessment, and monitoring.
- Crucial for overall financial reporting reliability.
- Consistency and communication are harder in decentralized organizations.
Memory trick: Decentralized means 'ENTITY' controls are 'RISKY'.
Auditor Response to Significant Risks
Flip cardFor significant risks, the auditor must perform substantive procedures that are specifically responsive to that risk, and may need to involve specialists, perform tests of controls if reliance is intended, and consider unpredictable audit procedures.
- Requires specific substantive procedures.
- May involve specialists for complex areas.
- Mandates evaluation of controls if reliance is planned.
Memory trick: Complex risk? Call in the experts and dig deep!
Materiality - User Sensitivity
Flip cardMateriality is the magnitude of an omission or misstatement of accounting information that, in light of surrounding circumstances, makes it probable that the judgment of a reasonable person relying on the information would have been changed or influenced by the omission or misstatement. It is influenced by the needs and sensitivity of financial statement users.
- Auditor professional judgment is key.
- Quantitative and qualitative factors considered.
- Lower materiality means more audit work needed.
Memory trick: Squeezed profits and tight covenants mean 'lower' wiggle room for error.
Inherent Risk Factors
Flip cardInherent risk is the susceptibility of an assertion about a class of transaction, account balance, or disclosure to a material misstatement, assuming there are no related controls.
- Exists independently of the audit.
- Affected by business characteristics, industry, and complexity.
- Higher for complex transactions, estimates, or new business lines.
Memory trick: Inherent risks are 'baked in' to the business before controls even start.
Inherent Risk - Regulatory Complexity
Flip cardThe susceptibility of an assertion to a misstatement that could be material, individually or in aggregate, before consideration of any related controls, due to the complexity of regulations affecting the entity's transactions.
- Increases with the number and intricacy of rules.
- Often impacts revenue recognition, provisions, and contingent liabilities.
- Requires specialized knowledge to assess and audit.
Memory trick: Complex Rules Tangle the True Value.
COSO - Monitoring Activities
Flip cardMonitoring activities are ongoing evaluations, separate evaluations, or a combination of both, used to ascertain whether the components of internal control are present and functioning. They ensure the continued effectiveness of internal control over time.
- Includes internal audit, supervisory reviews, and self-assessments.
- Ensures controls are operating as intended.
- Timely communication of deficiencies is crucial.
Memory trick: Monitoring is the 'watchdog' keeping controls in check.
Fraud Triangle - Incentive/Pressure
Flip cardOne of the three conditions of the fraud triangle, representing a reason or motivation for management or employees to commit fraud, often stemming from financial targets, personal financial distress, or internal pressures.
- Motivation for fraud.
- Often financial or performance-based.
- Examples: bonuses tied to earnings, debt covenants.
Memory trick: PIO: Pressure, Opportunity, Rationalization.
Inherent Risk - New Systems
Flip cardNew or significantly changed information systems and processes can introduce inherent risks to financial reporting due to lack of established controls, unfamiliarity, or complexity, particularly affecting revenue, inventory, and related accounts.
- Increases susceptibility to misstatement.
- Often impacts revenue recognition and inventory.
- Requires careful assessment during planning.
Memory trick: New sales methods mean new ways for numbers to go wrong.
Service Organization Control (SOC) 1 Report
Flip cardA report issued by a service organization's auditor to provide information about the service organization's internal controls over financial reporting relevant to a user entity's financial statements.
- Type 1 reports on design of controls at a specific date.
- Type 2 reports on design and operating effectiveness over a period.
- Essential for auditing clients using outsourced services impacting financial reporting.
Memory trick: SOC-kets connect client to service controls.
Going Concern
Flip cardThe assumption that an entity will continue to operate indefinitely, without the intention or necessity to liquidate or cease operations in the foreseeable future (typically 12 months from the financial statement date).
- Auditor must evaluate if substantial doubt exists.
- Indicators include financial, operating, and other matters.
- Requires specific audit procedures and disclosures if doubt exists.
Memory trick: Going Concern: 'Financial, Operating, Other' signs of trouble.
Inherent Risk - System Implementation
Flip cardThe susceptibility of an assertion to a material misstatement, assuming there are no related controls, specifically exacerbated by the complexities and uncertainties of new system implementations or data migrations.
- Data migration is a major source of inherent risk.
- Customization and integration issues increase risk.
- Impacts multiple financial statement assertions.
Memory trick: New systems bring 'Data Dangers, Design Doubts, and Transition Troubles'.
Audit Risk Model & Control Risk
Flip cardThe Audit Risk Model (AR = IR x CR x DR) illustrates the inverse relationship between control risk (CR) and detection risk (DR); a lower assessed control risk allows for a higher acceptable detection risk, leading to less substantive testing.
- AR = Audit Risk, IR = Inherent Risk, CR = Control Risk, DR = Detection Risk.
- Auditor controls DR by adjusting substantive procedures.
- Effective controls reduce CR, allowing reduced DR (less substantive testing).
Memory trick: Low Controls, Less Detections, Less Substantives.
Management Override of Controls
Flip cardThe ability of management to circumvent internal controls, often through non-routine transactions or by influencing accounting judgments, leading to potential material misstatements.
- A significant fraud risk factor.
- Often involves estimates and complex transactions.
- Difficult to detect through traditional control testing.
Memory trick: Override is when 'The Boss Breaks Barriers'.
Inherent Risk - Decentralized Operations
Flip cardThe susceptibility of financial statement assertions to material misstatement, assuming no related internal controls, which is elevated in decentralized environments due to variations in processes, oversight, and potential for inconsistent application of policies at individual locations.
- Higher volume of transactions at multiple points increases error risk.
- Variations in local management and staff expertise.
- Challenges in consistent application of policies and procedures.
Memory trick: Decentralized means 'Different Doors for Discrepancies'.
Assessing Control Risk in Decentralized Entities
Flip cardFor entities with distinct operating segments or decentralized structures, control risk is often assessed separately for each significant component due to varying control environments and systems.
- Each segment may have different control strengths/weaknesses.
- Tailored audit approach for each segment is often more efficient.
- Entity-level controls still need to be considered for overall impact.
Memory trick: Decentralized means 'Divide and Conquer Controls'.
Positive Assurance
Flip cardPositive assurance is a high, but not absolute, level of assurance provided in an examination engagement, where the practitioner expresses an opinion on the subject matter.
- Highest level of assurance in attestation engagements.
- Expressed as an explicit opinion (e.g., 'In our opinion...').
- Requires extensive procedures and evidence gathering.
Memory trick: Examine Positively, Review Limiting, Compile None.
Going Concern Mitigation Evidence
Flip cardAudit evidence supporting management's plans to alleviate substantial doubt about an entity's ability to continue as a going concern.
- Evidence must be persuasive and verifiable.
- Focus on specific, actionable plans with external support.
- Management's assertions alone are insufficient.
Memory trick: When the company's future looks grim, strong evidence is key to make it swim.