Free Questions › CPA › Auditing and Attestation
Free CPA Auditing and Attestation Practice Questions & Answers
500 exam-style Auditing and Attestation questions. Pick your answer, hit Check answer, and see the worked solution — free to start, no signup.
100% free · No login to startQuestion 1
An auditor has set audit risk at 5%, assessed inherent risk at 60% and control risk at 50%. What is the maximum acceptable level of detection risk?
Select an option first.
Correct answer: D — 16.7%
Explanation: Rearranging the audit risk model AR = IR x CR x DR gives DR = AR / (IR x CR) = 0.05 / (0.60 x 0.50) = 0.05 / 0.30 = 0.1667, or approximately 16.7%. Detection risk is the only component the AUDITOR controls — inherent and control risk belong to the client and are assessed, not set. Option C multiplies rather than divides. Option B is the RMM (IR x CR = 30%), which is the client-side risk, not detection risk. Option A simply restates audit risk.
Question 2
Wexler Chemical has weak controls over its inventory count and operates in an industry with volatile commodity prices. Compared with a lower-risk client, the auditor should:
Select an option first.
Correct answer: C — Accept a lower level of detection risk and perform more or better substantive procedures
Explanation: High inherent risk (volatile prices) combined with high control risk (weak count controls) produces a high RMM. Because AR is held constant at a low level, a higher RMM forces a LOWER acceptable detection risk — which the auditor achieves by performing MORE or BETTER substantive procedures, changing their nature, timing (closer to year-end) and extent. Option D reverses the relationship. Option A is wrong because audit risk is SET by the auditor at a low level; it is not something that rises with the client's riskiness.
Question 3
Which of the following is a required risk assessment procedure in EVERY audit?
Select an option first.
Correct answer: D — Analytical procedures performed during planning
Explanation: Risk assessment procedures — required in every audit — are INQUIRY of management and others, ANALYTICAL PROCEDURES (preliminary), and OBSERVATION and INSPECTION. Preliminary analytical procedures are therefore mandatory. Options A, B and C are all SUBSTANTIVE procedures or tests of details; they may or may not be performed depending on the risks identified. Critically, risk assessment procedures alone do NOT provide sufficient appropriate audit evidence about the assertions — they identify where to look, they do not constitute the looking.
Question 4
Ashgrove Retail reports revenue of $50 million, total assets of $30 million, and pre-tax income of $1.2 million. The auditor considers pre-tax income the most appropriate benchmark. Using a 5% benchmark, overall materiality would be approximately:
Select an option first.
Correct answer: B — $60,000
Explanation: 5% of pre-tax income of $1.2 million is $60,000. Common benchmarks are 0.5% to 1% of revenue or total assets, 5% to 10% of pre-tax income, and 1% to 2% of equity. Note how much SMALLER the income-based figure is here: 0.5% of revenue would be $250,000 and 1% of assets would be $300,000. When a company has thin margins, an income benchmark produces a very low materiality — which is precisely why benchmark SELECTION is a matter of judgement, and why an auditor may choose a more stable benchmark when earnings are volatile or near break-even.
Question 5
Performance materiality is set BELOW overall materiality principally to:
Select an option first.
Correct answer: B — Reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality
Explanation: Performance materiality (commonly 50% to 75% of overall materiality) exists to address AGGREGATION RISK — the possibility that many individually immaterial misstatements, added together, exceed overall materiality. Without this buffer, an auditor could pass on dozens of small errors and still end up with materially misstated financial statements. Option D misstates the purpose: performance materiality does not guarantee anything about individual items. Option C invents a regulatory source, and option D confuses a planning tool with a reporting outcome.
Get the full CPA question bank — free
Drop your email and we'll send you fresh CPA practice questions, fully worked solutions and exam-deadline reminders. No spam — unsubscribe in one click.
Want to save your score and take a full mock exam? Create a free account →
Question 6
Which of the following is an INHERENT risk factor rather than a control risk factor?
Select an option first.
Correct answer: D — The client holds significant inventory of high-value, easily portable goods
Explanation: INHERENT risk is the susceptibility of an assertion to misstatement BEFORE considering any controls — it arises from the nature of the business, the account, or the transaction. High-value, easily portable inventory (jewellery, microchips) is inherently susceptible to theft, regardless of what controls exist. Options A, B and C all describe deficiencies in the CONTROL environment or in specific controls; they are control risk factors. The distinction matters because the auditor cannot change inherent risk — it is a property of the client's business.
Question 7
The COSO framework's control environment component is best described as:
Select an option first.
Correct answer: D — The foundation for all other components, encompassing integrity, ethical values and the tone at the top
Explanation: The CONTROL ENVIRONMENT is the FOUNDATION of the COSO framework — it sets the tone of the organisation and influences the control consciousness of its people, encompassing integrity, ethical values, board oversight, organisational structure and commitment to competence. Option A describes CONTROL ACTIVITIES. Option C describes RISK ASSESSMENT. Option B describes MONITORING. The reason the control environment ranks first is that a weak one undermines every other component: no volume of control activities can compensate for a management team willing to override them.
Question 8
For a significant risk, the auditor MUST:
Select an option first.
Correct answer: B — Perform substantive procedures specifically responsive to that risk
Explanation: For a SIGNIFICANT RISK, substantive procedures specifically responsive to that risk are MANDATORY. The auditor may NOT rely on controls alone, no matter how effectively those controls tested. This is an absolute rule and the exam is fond of absolutes. Option C is not required — the auditor may choose to test controls, but doing so never removes the substantive requirement. Option D is a standard procedure for every audit and is not a response to a significant risk. Option A inverts the correct response: higher risk calls for MORE work, not less.
Question 9
Under AU-C 240, an auditor must presume that a fraud risk exists in relation to:
Select an option first.
Correct answer: B — Revenue recognition
Explanation: The auditor must PRESUME that there is a fraud risk in REVENUE RECOGNITION. That presumption may be REBUTTED, but the rebuttal — and the reasons for it — must be documented. In addition, the auditor must ALWAYS test for management override of controls, regardless of the assessed risk, because management can defeat the very controls it designed. Options A, C and D are all areas that commonly give rise to significant risks, but none carries a mandatory presumption in the standards.
Question 10
Which combination would most likely lead an auditor to conclude that a significant risk exists?
Select an option first.
Correct answer: D — A complex, non-routine transaction involving a related party and a subjective valuation
Explanation: Significant risks are typically associated with COMPLEXITY, NON-ROUTINE transactions, RELATED PARTIES, SUBJECTIVE ESTIMATES and FRAUD potential. Option D stacks three of these at once. Options A, C and B describe routine, systematic, objectively verifiable transactions — precisely the profile that does NOT produce a significant risk. The consequence matters: a significant risk conclusion forces substantive procedures and rules out sole reliance on controls.
Question 11
An auditor is evaluating going concern for Palliser Freight. Substantial doubt must be evaluated over a period of:
Select an option first.
Correct answer: A — One year from the date the financial statements are issued or available to be issued
Explanation: Under ASC 205-40, substantial doubt is evaluated for ONE YEAR FROM THE DATE THE FINANCIAL STATEMENTS ARE ISSUED (or available to be issued) — NOT from the balance sheet date. Because financial statements are typically issued two to four months after year-end, this effectively extends the lookout period well beyond twelve months from year-end. Option B applies the older, superseded convention and is the most attractive distractor. Getting the starting point right changes which events fall inside the assessment window.
Question 12
Which assertion is MOST directly addressed by tracing shipping documents to entries in the sales journal?
Select an option first.
Correct answer: B — Completeness
Explanation: TRACING from source documents FORWARD to the accounting records tests COMPLETENESS — it detects UNDERSTATEMENT, because you begin with evidence of a transaction that occurred and check that it was recorded. Starting in the sales journal could never find an unrecorded sale, because an unrecorded sale is not there. The reverse direction — VOUCHING from the journal back to shipping documents — tests OCCURRENCE and detects OVERSTATEMENT. Direction of testing determines which error you are capable of finding, and it is one of the highest-yield concepts in AUD.
Question 13
The auditor of Bracknell Utilities plans to rely on an automated three-way match control within the client's ERP system. Before doing so, the auditor must be satisfied that:
Select an option first.
Correct answer: D — The relevant IT general controls, particularly change management, are operating effectively
Explanation: An automated application control can be relied upon only if the underlying IT GENERAL CONTROLS — especially CHANGE MANAGEMENT and logical access — are effective. If a developer could alter the control's logic mid-year without approval, then testing the control once tells you nothing about the rest of the period. This dependency is the central logic of IT auditing. Option B defeats the purpose of automation. Option A names the wrong report (a SOC 3 is a public marketing summary). Option C relies on management representation alone, which is never sufficient evidence.
Question 14
An increase in the assessed risk of material misstatement would ordinarily lead the auditor to:
Select an option first.
Correct answer: C — Use larger sample sizes and shift testing closer to year-end
Explanation: A higher RMM demands a lower detection risk, which the auditor achieves by changing the NATURE (more reliable procedures), TIMING (closer to or at year-end rather than at an interim date) and EXTENT (larger samples) of substantive procedures. Option B moves testing in the wrong direction — interim testing leaves a roll-forward period exposed. Option D leans on the weakest form of evidence there is. Option A would REDUCE the work performed, which is the opposite of the correct response.
Question 15
Which of the following would an auditor LEAST likely perform as part of understanding the entity and its environment?
Select an option first.
Correct answer: C — Confirming the year-end accounts receivable balances
Explanation: CONFIRMATION of receivables is a substantive test of details — it obtains evidence about an assertion, and it is performed after risks have been assessed and a response designed. Options A, B and D are all risk assessment procedures used to understand the entity: reading minutes (inspection), preliminary analytics, and inquiry. The distinction is fundamental — risk assessment procedures tell you WHERE to look; substantive procedures are the looking.
Question 16
Tolerable misstatement is best described as:
Select an option first.
Correct answer: C — An amount applied to a specific account balance or class of transactions, set at or below performance materiality
Explanation: TOLERABLE MISSTATEMENT is applied at the level of an individual ACCOUNT BALANCE or class of transactions, and is set at or below PERFORMANCE materiality. The hierarchy runs: overall materiality (the financial statements as a whole) → performance materiality (a buffer against aggregation risk) → tolerable misstatement (applied to a specific account). Option D describes overall materiality. Option B describes the clearly trivial threshold, which is typically about 5% of overall materiality. Option A confuses a planning benchmark with a reporting decision.
Question 17
An entity's internal audit function can be used by the external auditor to provide DIRECT ASSISTANCE only if:
Select an option first.
Correct answer: D — The external auditor evaluates the internal auditors' competence and objectivity, and directs, supervises and reviews their work
Explanation: Where direct assistance is permitted, the external auditor must EVALUATE the internal auditors' COMPETENCE and OBJECTIVITY and must DIRECT, SUPERVISE AND REVIEW their work. The external auditor retains sole responsibility for the opinion — that responsibility can never be shared or delegated. Option C actually UNDERMINES objectivity, since reporting to the CFO compromises independence from the very function being audited; internal audit should report to the audit committee. Note also that direct assistance is prohibited altogether in PCAOB issuer audits.
Question 18
Which of the following most strongly indicates a material weakness in internal control?
Select an option first.
Correct answer: D — Identification of fraud by senior management, of any magnitude
Explanation: Identification of FRAUD BY SENIOR MANAGEMENT — of ANY magnitude — is a strong indicator of a material weakness. The reasoning is that the control environment itself has failed, and senior management is the one group capable of overriding every other control. Options B, C and A describe controls WORKING (the client caught it) or isolated, immaterial errors — neither of which indicates a deficiency severe enough to be a material weakness. Severity, not size, is the test.
Question 19
An auditor is required to communicate significant deficiencies and material weaknesses:
Select an option first.
Correct answer: B — In writing, to those charged with governance and to management
Explanation: Significant deficiencies and material weaknesses must be communicated IN WRITING to THOSE CHARGED WITH GOVERNANCE and to MANAGEMENT. The communication must be written — an oral discussion is not sufficient — and it should be made in a timely manner, ideally by the report release date. Option D is deficient in both audience and form. Option A invents a filing obligation. Option C wrongly makes a mandatory communication optional.
Question 20
When the auditor plans to use the work of a MANAGEMENT'S SPECIALIST (for example, an actuary engaged by the client to value pension obligations), the auditor must:
Select an option first.
Correct answer: A — Evaluate the specialist's competence, capabilities and objectivity, and evaluate whether the work is adequate for the auditor's purposes
Explanation: For a MANAGEMENT'S specialist, the auditor evaluates the specialist's COMPETENCE, CAPABILITIES and OBJECTIVITY, obtains an understanding of the work, and evaluates whether it is ADEQUATE AS AUDIT EVIDENCE. The auditor may NOT refer to the specialist in an unmodified report to divide responsibility (option A) — the auditor's responsibility for the opinion is undivided. Option C is not required, though engaging the auditor's OWN specialist is one possible response where the risk is high. Option B is too absolute: a lack of independence from the client is a factor to weigh, not an automatic bar.
Question 21
Rothsay Beverages uses a service organisation, Vantage Payroll Inc., to process all payroll transactions. Rothsay's auditor obtains a SOC 1 Type 2 report on Vantage. The report uses the CARVE-OUT method for Vantage's own cloud hosting subservice provider. The auditor should:
Select an option first.
Correct answer: A — Obtain evidence about the hosting subservice provider's controls, because they are excluded from the report
Explanation: Under the CARVE-OUT method the subservice organisation's controls are EXCLUDED from the report. That leaves a hole in the auditor's assurance, and it is the USER auditor's job to fill it — typically by obtaining a separate SOC report on the hosting provider, or by performing procedures directly. The carve-out does not eliminate the risk; it shifts the work to the user. Relying on the report in full ignores the gap. Demanding reissue is not a realistic or required response, and a disclaimer is a wildly disproportionate reaction to a routine reporting convention.
Question 22
An auditor is designing procedures for a client whose entire revenue cycle is automated with no manual intervention. Tests of controls are:
Select an option first.
Correct answer: C — Likely to be efficient, because an automated control operates consistently once its logic is verified and IT general controls are effective
Explanation: An automated control operates CONSISTENTLY — it applies the same logic every time, so testing a small number of instances can support reliance for the whole period, PROVIDED IT general controls (especially change management) are effective. That combination makes testing automated controls unusually efficient. It does not make them infallible: the logic itself may be wrong, and a programme change could alter it mid-period, which is exactly why the ITGC dependency matters. Testing every transaction would defeat the efficiency the automation offers.
Question 23
Which condition would MOST likely cause an auditor to increase the assessed inherent risk for revenue?
Select an option first.
Correct answer: C — The client offers bundled contracts with multiple performance obligations and variable consideration
Explanation: INHERENT risk rises with COMPLEXITY and JUDGEMENT. Bundled contracts with multiple performance obligations require allocation on relative standalone selling price, and variable consideration requires estimation and constraint — both are judgement-heavy and therefore inherently more susceptible to misstatement. A single product at a fixed price settled in cash is about as simple as revenue gets. Steady, unremarkable growth and a standard ERP module do not, by themselves, elevate inherent risk.
Question 24
Prevailing audit standards require the auditor to test management override of controls:
Select an option first.
Correct answer: A — In every audit, regardless of the assessed level of risk
Explanation: Testing for MANAGEMENT OVERRIDE is MANDATORY in every audit, regardless of the assessed risk. The reasoning is structural: management is uniquely able to defeat the very controls it designed, so no assessment of control effectiveness can rule it out. Required procedures include examining journal entries (especially non-standard ones and those posted at period-end), reviewing accounting estimates for bias, and evaluating the business rationale of significant unusual transactions. This is one of the few unconditional requirements in the standards.
Question 25
An auditor identifies a risk that inventory is obsolete and overstated. Which of the following is the MOST responsive procedure?
Select an option first.
Correct answer: B — Reviewing inventory turnover by product line and inspecting slow-moving items on site
Explanation: The risk identified is a VALUATION risk (obsolescence), so the response must address valuation. Reviewing turnover by product line identifies slow-moving stock, and physically inspecting those items provides evidence about their condition and saleability. Option D addresses a quantity or rights question, and suppliers do not hold the client's inventory in any event. Option C tests clerical ACCURACY, not obsolescence — the arithmetic can be flawless on goods that are worthless. Option A tests COMPLETENESS. The procedure must match the assertion at risk.
Question 26
Analytical procedures performed as part of RISK ASSESSMENT differ from SUBSTANTIVE analytical procedures in that risk assessment analytics:
Select an option first.
Correct answer: D — Are designed to identify unusual relationships and potential risk areas, not to provide evidence about an assertion
Explanation: RISK ASSESSMENT analytics are performed at a high level in PLANNING to identify unusual or unexpected relationships and to direct attention to areas of higher risk. They are required in every audit, but they do NOT provide evidence about assertions. SUBSTANTIVE analytics, by contrast, are designed to obtain evidence, and therefore demand a far more PRECISE expectation, a defined tolerable difference, and investigation of variances. Confusing the two leads auditors to believe a planning analytic has substantiated a balance. It has not.
Question 27
Which of the following circumstances would ordinarily require the auditor to reassess the risk of material misstatement DURING the audit?
Select an option first.
Correct answer: A — Testing reveals a control deviation rate materially higher than expected
Explanation: Risk assessment is CONTINUOUS, not a one-off planning exercise. If testing reveals a deviation rate materially above expectation, the auditor's original control risk assessment was wrong, and detection risk must be lowered — meaning more or better substantive procedures. Other triggers for reassessment include discovering fraud, identifying an unrecorded transaction, or finding that management's explanations are inconsistent with other evidence. Options C, B and D have no bearing on the susceptibility of the financial statements to misstatement.
Question 28
Kelso Marine capitalises interest on self-constructed vessels and applies significant judgement in estimating the useful lives of its fleet. In assessing risk, the auditor should regard these accounting estimates as:
Select an option first.
Correct answer: D — Areas warranting particular audit attention, because estimates are susceptible to management bias
Explanation: ACCOUNTING ESTIMATES are inherently susceptible to MANAGEMENT BIAS, because they involve subjective judgement and often have a direct effect on reported earnings. The auditor must evaluate whether the estimates are reasonable and whether there are indicators of bias — including a pattern of estimates that consistently push earnings in one direction. Having a documented policy (option A) does not remove the judgement. Option A overstates the response: developing an independent point estimate is ONE possible procedure, not a universal requirement.
Question 29
An auditor plans to test controls at an INTERIM date, three months before year-end. To rely on those results at year-end, the auditor must:
Select an option first.
Correct answer: C — Obtain evidence about the remaining period, such as testing controls over the roll-forward period or performing substantive procedures
Explanation: Testing at an interim date leaves a ROLL-FORWARD PERIOD (here, three months) uncovered. To rely on the interim results, the auditor must obtain evidence about that remaining period — typically by testing the controls' continued operation, by inquiring about changes, and by performing substantive procedures over the intervening transactions. Doing nothing (option A) leaves a gap in coverage. Re-performing everything (option C) discards the efficiency that interim testing was meant to create. Lowering materiality (option D) does not address the timing gap at all.
Question 30
An auditor sets audit risk at 3%, inherent risk at 80% and control risk at 75%. Detection risk is approximately:
Select an option first.
Correct answer: A — 5.0%
Explanation: DR = AR / (IR x CR) = 0.03 / (0.80 x 0.75) = 0.03 / 0.60 = 0.05, or 5%. Note how a high RMM (60%) forces detection risk down to a very low level, requiring extensive substantive work. Multiplying instead of dividing gives 1.8%. The 60% figure is the RMM itself, not detection risk.
More free CPA topics
Ten questions in
- The ones you miss are saved as a drill you can repeat
- Your place is kept, on this device and any other
- A streak, if that is the thing that gets you back tomorrow
Every question on this page stays free and open either way.