2.0 Assessing Risk and Developing a Planned Response AUD Practice Quiz
86 exam-style questions covering 30% of the AUD exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CPA Auditing and Attestation (AUD) practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Establishing an overall audit strategy at the beginning of an engagement serves to
- A. Set the scope, timing, and direction of the audit and guide the development of the more detailed engagement plan
- B. Provide a fixed, unchangeable schedule of procedures to be completed before the audit report is issued
- C. Document the specific account balances the auditor plans to confirm and the sample sizes for each area
- D. Satisfy the legal requirement that all audit procedures be disclosed to management before field work begins
AU-C Section 300 requires the auditor to establish an overall audit strategy that sets the scope, timing, and direction of the audit and guides the development of the audit plan. The strategy addresses the characteristics of the engagement (entity size, industry, reporting requirements), the reporting objectives (form and timing of reports), the significant factors that determine the engagement team's focus, the results of preliminary engagement activities, and the nature, timing, and extent of resources the firm expects to deploy.
Which of the following decisions is BEST characterized as part of the overall audit strategy rather than the more detailed engagement plan?
- A. The specific customers selected for accounts receivable confirmation and the monetary threshold below which alternative procedures will be applied
- B. The determination that the audit will rely primarily on substantive analytical procedures rather than tests of controls in areas where the assessed control environment is weak
- C. The identification of which accounting estimates will require the use of an external specialist
- D. The specific document inspection procedures to be applied to a sample of revenue transactions
The decision to rely on substantive analytical procedures rather than tests of controls for areas with weak control environments is a strategic-level decision. The overall strategy determines the general approach, for example, whether the audit will be primarily controls-reliance based (tests of controls followed by reduced substantive procedures) or primarily substantive (direct testing of financial statement assertions with little or no reliance on controls). This direction-setting decision flows into the engagement plan, which specifies the actual procedures.
During preliminary planning for a manufacturing company's audit, the auditor learns the entity completed a major acquisition during the year, adding a new business line with different accounting systems and separate internal controls. How does this information MOST affect the overall audit strategy?
- A. It has no effect on the strategy since acquisitions are disclosed in the footnotes and are not a primary audit risk
- B. It reduces the audit scope because the acquired entity will be separately audited by another firm
- C. It increases audit complexity and risk, the strategy should expand scope to include procedures specific to the acquired business, its accounting systems, and the accounting treatment of the acquisition itself
- D. It requires the auditor to immediately resign and allow a firm specializing in mergers and acquisitions to lead the engagement
A significant acquisition fundamentally changes the engagement. The auditor must expand the overall strategy to: assess new risks introduced by the acquired business; plan for understanding and testing the acquired entity's accounting systems and internal controls; address the accounting for the acquisition (purchase price allocation, contingent consideration, goodwill impairment testing if applicable); and consider whether specialists are needed to evaluate complex fair value measurements.
After the overall audit strategy is established and field work is underway, the auditor discovers that the entity restated a prior-year financial statement due to a previously undetected error in revenue recognition. How should the auditor respond to this discovery?
- A. No response is required, prior-year restatements are management's responsibility and do not affect the current-year audit strategy
- B. Revise the overall audit strategy and engagement plan to reflect the increased assessed risk, and perform additional procedures responsive to the heightened risk of misstatement in revenue recognition
- C. Issue a preliminary audit opinion on the restatement before concluding the current-year audit
- D. Resign from the engagement because the restatement indicates management lacks integrity and cannot be trusted
A prior-year restatement, particularly in revenue recognition, is a direct indicator of elevated risk in the current year. The auditor should: (1) reassess the risk of material misstatement in revenue recognition and related accounts; (2) consider whether the control failures that produced the prior error have been remediated; (3) expand substantive testing in the affected areas; and (4) apply heightened professional skepticism to management's current-year revenue recognition judgments. The strategy and plan should be updated to reflect this information.
During testing of a client's revenue transactions, an auditor discovers a significant related-party transaction that was not identified during preliminary risk assessment. The auditor's MOST appropriate response regarding the engagement plan is to
- A. Complete all planned procedures first before addressing the newly identified information, to avoid disrupting the original plan
- B. Document the discovery but defer any plan modifications until the following year's audit, when more complete information will be available
- C. Issue a preliminary adverse opinion due to the late discovery of related-party transactions
- D. Update the engagement plan to include additional procedures designed to address the newly identified related-party risk, and consider whether the overall strategy also needs revision
AU-C 300 explicitly requires the auditor to update the audit plan when new information becomes available that requires modification of planned procedures. The discovery of a previously unidentified significant related-party transaction warrants: (1) designing additional procedures to understand the nature, terms, and business purpose of the transaction; (2) assessing whether the transaction has been properly disclosed and measured; and (3) considering whether the overall strategy requires revision based on the revised risk assessment.
A specialty retailer faces mounting competitive pressure from online alternatives, narrowing margins, and several industry peers that recently filed for bankruptcy. In developing the overall audit strategy, how should the auditor MOST appropriately respond to this external environment?
- A. The external competitive environment is management's concern, the overall strategy should remain unchanged and focus on verifying reported account balances
- B. The auditor should withdraw from the engagement since a potentially failing industry creates unacceptable audit risk
- C. The strategy should emphasize payroll procedures, since retailers in competitive industries tend to understate labor costs
- D. The strategy should direct increased audit attention to inventory valuation, asset impairment, going concern assessment, and revenue recognition, areas most likely to be affected by the competitive pressures and associated management pressure to present favorable results
A challenging competitive environment with declining industry performance creates elevated incentives for management to present favorable financial results, which increases fraud risk and the risk of aggressive accounting. The overall strategy should acknowledge these elevated risks and direct resources and emphasis to the financial statement areas most affected by the operating environment, particularly those requiring significant estimates and judgments.
In planning the audit of a financial services company, the auditor identifies that the valuation of complex structured financial instruments is a significant risk. When developing the engagement plan's procedures for this risk, the auditor should
- A. Design procedures specifically responsive to the significant risk, such as engaging a valuation specialist, obtaining independent pricing from external sources, and applying heightened skepticism to management's assumptions and models
- B. Assign the valuation area to the least experienced team member, since it requires only basic recalculation skills
- C. Reduce testing of other accounts to allow additional time for discussing the valuation with management
- D. Accept management's valuation without independent verification since fair value measurements are inherently subjective and not subject to meaningful audit challenge
AU-C 330 and AU-C 540 require that significant risks, those requiring special audit consideration, have specifically designed responsive procedures that go beyond the standard procedures applied to lower-risk areas. For complex financial instrument valuations, this typically includes: engaging a valuation specialist (AU-C 620) who can independently assess the methodology and key assumptions; obtaining independent pricing from third-party pricing services or market data; testing the significant assumptions (discount rates, volatility, credit spreads) for reasonableness; and reviewing management's valuation models for mathematical accuracy and conceptual soundness.
An auditor identifies a high risk of material misstatement in revenue recognition for a software company with complex multi-element arrangements. When translating this risk assessment into the engagement plan, the auditor should
- A. Accept management's revenue recognition policy as reasonable because the FASB's ASC 606 guidance was specifically designed to address multi-element arrangements and management would not depart from it
- B. Request that management revise its revenue recognition policy to one that the auditor can more easily test
- C. Identify revenue recognition as a significant risk in the documentation but rely solely on management's representations for this area since it involves significant judgment
- D. Develop specific substantive procedures responsive to the risk, such as detailed contract review, testing of the identification and allocation of performance obligations, and inspection of customer acceptance documentation, in addition to any planned tests of controls
Significant risks, as defined in AU-C 315, require specifically designed responsive procedures. For complex revenue arrangements, this means: reviewing a sample of contracts to evaluate management's identification of performance obligations; testing the transaction price allocation among performance obligations using the standalone selling price (or estimation method) specified by ASC 606; inspecting evidence of performance obligation satisfaction (e.g., delivery records, customer acceptance documentation); and assessing the reasonableness of management's judgment calls on constrained variable consideration. Reliance on controls alone, without substantive procedures, is not permitted for significant risks.
Key Terms in This Domain
- Risk Assessment Procedures: Inquiry, observation, inspection, and analytical procedures used to identify and assess risks of material misstatement at the financial-statement and assertion level.
- Misstatements and Internal Control Deficiencies: Summary of corrected and uncorrected misstatements; classification of deficiencies as control deficiency, significant deficiency, or material weakness.
- COSO Internal Control: Integrated Framework: Five components and seventeen principles used to define and evaluate internal control over financial reporting in audit risk assessment.
- SOC 1® Type 2 Reports: Used by user-entity auditors to evaluate controls at service organizations relevant to user-entity ICFR; informs nature/timing/extent of testing.
- Materiality: Quantitative and qualitative threshold for misstatements; includes performance materiality (tolerable misstatement) applied at the account/disclosure level.
- Tests of Controls vs. Tests of Details: Operating-effectiveness procedures vs. substantive procedures to detect dollar misstatements at the assertion level.
- Communication with Those Charged with Governance: Required communications on planned scope and timing, identified deficiencies, material weaknesses, and significant audit findings.
- IT General Controls: Access management, change management, and IT operations controls that support the reliability of application-level controls.
- Fraud Risk: Identification of pressures, incentives, and opportunities for fraudulent financial reporting and misappropriation of assets; required response considerations.
- Audit Sampling: Statistical or nonstatistical sampling techniques for tests of controls (attribute) and tests of details (variables); includes stratification and extrapolation.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/cpa-aud/assessing-risk-and-planned-response/
<a href="https://quizbuffet.com/cpa-aud/assessing-risk-and-planned-response/">CPA AUD (Auditing and Attestation) Assessing Risk and Developing a Planned Response practice quiz on QuizBuffet</a>
Other AUD Domains
- 1.0 Ethics, Professional Responsibilities and General Principles
- 3.0 Performing Further Procedures and Obtaining Evidence
- 4.0 Forming Conclusions and Reporting
← Back to AUD practice test overview
Questions are written against the published AUD objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.