Study Guide

AUD CPA Exam Study Guide: Assurance Levels and Evidence

Learn how to anchor every AUD question to its engagement type and evidence concept, with worked scenarios, an opinion decision table, and a self-check drill…

Updated September 20269 min readStudy GuideCPA QuizBank
Audrey Watson

Audrey Watson

CPA QuizBank Editorial Team

Classify every AUD item by engagement type and assurance level before reading options: audit (reasonable assurance, opinion), review (limited assurance), compilation (no assurance, report), preparation (no assurance, no report), and attestation (reasonable or limited assurance on subject matter). Then apply the matching evidence logic — sufficiency versus appropriateness and assertion mapping — and the reporting logic — the misstatement-versus-limitation, materiality-versus-pervasiveness grid that selects among unmodified, qualified, adverse, and disclaimer opinions.

Anchor every question to its engagement and assurance level before touching the choices

Every AUD item sits within one of the blueprint areas: audit, review, compilation, preparation, or attestation. Identify which service the stem describes and its assurance level — reasonable, limited, or none — before evaluating options.

An audit provides reasonable assurance through an opinion on the financial statements as a whole. A review of financial statements provides limited assurance based mainly on inquiries and analytical procedures. A compilation presents client information without assurance, accompanied by a report stating that no audit or review was performed. A preparation engagement produces financial statements with neither assurance nor a report. Attestation engagements apply examination, review, or agreed-upon-procedures work to subject matter or assertions rather than to financial statements, under separate attestation standards.

Make the classification mechanical. Rewrite each stem as three blanks: who the practitioner is serving, what output is delivered, and what assurance level attaches to it. A question describing inquiries and analyticals with limited assurance is a review question even if it mentions inventory; a question about a report stating that no assurance is provided is compilation or preparation territory. Reading the options before classifying lets plausible-sounding answers from neighboring service levels pull you away from the correct one.

Separate evidence sufficiency from evidence appropriateness

Sufficiency is quantity of evidence; appropriateness is its quality, combining relevance and reliability. A large volume of weak evidence never substitutes for a smaller amount of reliable, directly obtained evidence.

Reliability rises with the source and form of evidence: evidence obtained directly by the auditor outranks evidence obtained indirectly; external sources outrank internal ones; documents outrank oral representations; originals outrank copies. Relevance ties each procedure to a specific assertion — existence, completeness, valuation, rights and obligations, presentation and disclosure. When you compare two procedures, ask which one reaches the target assertion from a more independent source, not which one covers more balances on paper.

Worked scenario: a question asks which procedure best supports the existence of accounts receivable. Option A is the client's aged trial balance, reconciled and covering every balance; Option B is confirmations sent directly to a sample of customers. The tempting answer is A because it appears comprehensive. The better answer is B: existence needs evidence from outside the entity, and a management-prepared schedule cannot corroborate it regardless of its coverage. Choosing A confuses sufficiency with appropriateness — accumulating more internal documents does not repair weak source reliability, which is why the two concepts must be evaluated separately.

Use the risk model vocabulary precisely: inherent risk, control risk, RMM, detection risk

Risk of material misstatement combines inherent risk and control risk at the assertion level. Detection risk is the only component the auditor controls, through the nature, timing, and extent of procedures.

Inherent risk is susceptibility to misstatement before any controls; control risk is the chance that controls fail to prevent or detect a misstatement; their combination is risk of material misstatement. The planning model expresses audit risk as the product of risk of material misstatement and detection risk, so the assessed RMM drives the required response: an effective controls assessment permits reliance on those controls, while higher inherent risk demands more reliable evidence and procedures performed closer to period end.

Scenario: a walkthrough shows a key control is well designed, but a test of operating effectiveness finds it did not operate throughout the year. A tempting answer says the auditor can reduce substantive testing because the control exists. The defensible choice increases substantive procedures and reassesses control risk upward, because assessed control risk must reflect the results of operating-effectiveness tests, not design on paper. Vocabulary precision matters here: good design with ineffective operation is still a control risk problem, and calling it anything else leads to the wrong planned response.

Select the opinion type with a two-question grid

Two screens select the report: is the issue a misstatement or a scope limitation, and is it material but not pervasive or material and pervasive? Those four cells map to the four opinion types.

Start with nature. Misstatements — departures from the applicable financial reporting framework — lead to qualified or adverse opinions. Scope limitations — inability to obtain sufficient appropriate evidence — lead to qualified opinions or disclaimers. Then apply severity: a matter that is material but not pervasive qualifies the opinion; one that is material and pervasive produces an adverse opinion for misstatements and a disclaimer for limitations. The remaining cases receive unmodified opinions, sometimes with an emphasis-of-matter or other-matter paragraph added.

Worked scenario: the client refuses to let the auditor observe a physical inventory count covering one warehouse, and inventory is material. The tempting answer is an adverse opinion. The better answer is a qualified opinion: this is a scope limitation, not a misstatement, and a single segment of inventory is material but unlikely to pervade the statements. If the inability extended to inventory records as a whole, the limitation would be pervasive and the correct report would be a disclaimer. Matching the issue type first, then severity, prevents exactly this swap.

IssueMaterial but not pervasiveMaterial and pervasive
Misstatement (departure from the framework)Qualified opinionAdverse opinion
Scope limitation (insufficient evidence)Qualified opinionDisclaimer of opinion

Apply the AICPA conceptual framework: name the threat, then the safeguard

Use the AICPA Code's threat categories — self-interest, self-review, advocacy, familiarity, adverse interest, undue influence, and management participation — to classify a fact pattern, then identify safeguards that eliminate the threat or reduce it to an acceptable level.

Each threat has a recognizable signature: a financial interest in the client signals self-interest; auditing your own prior work signals self-review; promoting a client's securities signals advocacy; long or close personal relationships signal familiarity; litigation between the firm and client signals adverse interest; pressure from a client signals undue influence; taking on management duties signals management participation. Naming the threat first prevents generic answers such as decline the engagement in situations where a permitted safeguard exists.

Then run the framework: determine whether the threat is at an acceptable level; if it is not, apply safeguards such as rotating personnel, adding an independent second partner review, or removing the individual from the engagement. Distinguish independence in fact — the practitioner's actual state of mind — from independence in appearance — how a reasonable observer would view the relationship. A fact pattern can pass one test and fail the other, and ethics items turn on precisely that distinction, so evaluate both for every scenario you study.

Keep review, compilation, and preparation engagements distinct in your head

Review engagements deliver limited assurance from inquiries and analytical procedures; compilations deliver no assurance with a report; preparation engagements produce statements with no assurance and no report. Procedures, output, and reporting differ at every level.

In a review, the practitioner performs inquiries of management and analytical procedures, obtains a management representation letter, and reports limited assurance — the report communicates that nothing came to the practitioner's attention causing belief that the statements are materially misstated. In a compilation, the accountant presents information in financial statement form and reports that no audit or review was performed and no opinion or assurance is expressed. In a preparation engagement, the accountant prepares statements per the engagement terms and issues no report at all.

Anchor the distinctions to what changes and what stays constant. Assurance never exists in a compilation or preparation, so questions about confirmation, observation, or substantive testing belong to audits — though remember that a review has its own required procedures, and the practitioner could not simply omit the inquiries and analyticals. A review can also escalate: if evidence suggests the statements may be materially misstated, the practitioner asks management to investigate and consider amending them; failure to resolve the matter appropriately leads to withdrawal from the engagement.

Run a concepts week, a mixed-drills week, then a graded self-check

Split preparation into a concepts week and a mixed-drills week, then finish with a scored self-check: classify items before reading options and log every miss by concept and engagement type.

In week one, build one-page grids per blueprint area: rows for each service level with columns for procedures, assurance, and report; a matching grid for opinion types; and a threats-and-safeguards list you can reproduce from memory. In week two, shift to mixed question sets drawn across all areas, forcing you to switch between evidence, reporting, and ethics items the way the exam does. Keep an error log with two columns: the concept missed and the engagement type of the item, so patterns surface quickly.

Exercise: take ten mixed multiple-choice questions. For each, write down the engagement type, assurance level, and governing concept before looking at the options; afterwards, justify why each rejected option fails. Expected observations: classification takes noticeably less effort by the final items, and wrong answers begin to fail cleanly — a review option rejected because the stem described no assurance, or an adverse opinion rejected because the stem described a limitation. Self-check rubric: correctly classifying at least eight of ten is a solid learning milestone, not a passing prediction; score below that, return to the service-level grid before adding volume.

  • Reproduce the four-cell opinion table from memory in under a minute.
  • State the assurance level and report output for audit, review, compilation, preparation, and attestation services without notes.
  • For any pair of evidence items, say which is more reliable and why in one sentence.
  • Match each AICPA Code threat category to its signature fact pattern and one safeguard.
  • Maintain an error log tagging every miss by concept and engagement type.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for Uniform Certified Public Accountant Examination - Auditing and Attestation (AUD).

How is a preparation engagement different from a compilation if neither provides assurance?
The difference is output and reporting. A compilation results in financial statements presented by the accountant plus a report disclosing that no assurance is provided; a preparation engagement results in statements prepared under the engagement terms with no report at all. Classification questions turn on the presence or absence of that report.
Do I need to memorize every auditing standard number?
Concepts carry the section. Know what each report contains, what each evidence type supports, and which procedures belong to which service level. Recognizing report titles, key definitions, and framework terms matters far more than recalling citation numbers.
What is the difference between an attestation examination and an attestation review?
An examination provides reasonable assurance on subject matter or an assertion, expressed in a positive form; a review provides limited assurance, expressed in a negative form — nothing came to attention indicating the subject matter is misstated. The same reasonable-versus-limited logic that separates audits from reviews applies here.
Where do I handle application, scheduling, and score questions?
Eligibility, application processing, and score release are administrative matters handled through NASBA and your state board of accountancy. Check the NASBA CPA Exam page for current administrative details rather than relying on third-party summaries.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.