All questions
Question 1
An issuer is audited under PCAOB standards. The audit committee requests that the external auditor use internal audit's work extensively to reduce audit fees. Internal audit is competent but recently had high staff turnover, and several workpapers show inconsistent supervision and review. What is the most appropriate response when evaluating the internal audit function's work?
- Increase reliance to meet the audit committee's request because internal audit is part of the company's governance structure.
- Evaluate internal audit's competence and quality of work (including supervision and review), and limit reliance where documentation and execution are not sufficient, regardless of fee considerations. (correct answer)
- Rely on internal audit's work as long as internal audit staff sign independence confirmations each year.
- Apply AICPA review standards and rely on internal audit work as a substitute for obtaining audit evidence through substantive procedures.
Explanation: The concept being tested is PCAOB AS 1205, for internal auditors in issuer audits. Key facts include audit committee's reliance request for fee reduction, internal audit's competence but inconsistent supervision amid turnover. The correct answer follows AS 1205 by requiring evaluation of competence, work quality, limiting reliance if insufficient. Choice A is incorrect because governance does not override evaluation; choice C is wrong as confirmations are insufficient; choice D is erroneous since review standards are not for audits. For a transferable framework, auditors should assess supervision and documentation, avoid overreliance in cost-driven scenarios, and prioritize evidence quality over external pressures.
Question 2
A nonissuer technology company is undergoing a financial statement audit. The company has a shared service center that processes all cash receipts and accounts receivable for three domestic subsidiaries; a component auditor audited one subsidiary and tested controls at the shared service center for that subsidiary only. Based on the auditor's assessment, which factor should influence the reliance on component auditors?
- Use the component auditor's shared service center testing for all subsidiaries without further evaluation because the processes are centralized.
- Consider whether the component auditor's procedures and scope are relevant to the group audit (including whether controls tested apply to other components) and determine additional group-level procedures needed over shared service center controls and related balances. (correct answer)
- Rely on the component auditor only if they performed the work under PCAOB standards, regardless of the nonissuer status.
- Eliminate substantive testing of cash receipts because the component auditor tested controls at the shared service center.
Explanation: This question addresses using component auditor work for shared service center controls under AU-C 600. The critical facts are that the shared service center processes transactions for three subsidiaries, but the component auditor only tested controls for one subsidiary, creating a scope limitation. The correct answer (B) properly requires consideration of whether component procedures are relevant to the group audit, including control applicability to other components, and determination of additional procedures needed, consistent with standards requiring evaluation of work scope adequacy. Answer A incorrectly assumes centralized processes allow automatic extension of limited testing. Answer C inappropriately requires PCAOB standards for a nonissuer engagement. Answer D incorrectly eliminates substantive testing based on partial control testing. The professional framework emphasizes that shared service centers require holistic evaluation - control testing for one component may not provide sufficient evidence for all components using the service, requiring the group auditor to assess gaps and perform additional procedures to achieve appropriate audit coverage across all affected entities.
Question 3
An issuer parent company is undergoing a group audit. A foreign subsidiary audited by a component auditor contributes 35% of consolidated revenue and operates in a higher-risk jurisdiction; the component auditor is a separate firm within the same network, and the group engagement team has limited prior experience with that office. Based on the auditor's assessment, which factor should influence the reliance on component auditors?
- Rely primarily on the fact that the component auditor is in the same network and therefore no further involvement is necessary.
- Increase group engagement team involvement based on the component's significance and risk, including evaluating the component auditor's competence and independence and directing and reviewing their work. (correct answer)
- Avoid any communication with the component auditor to preserve independence and prevent undue influence.
- Apply AICPA nonissuer component auditor guidance and exclude the subsidiary from the scope because it is audited by another firm.
Explanation: This question tests AS 1205 requirements for group audits of issuers, focusing on component auditor reliance decisions. The key facts include the component's significance (35% of revenue), higher-risk jurisdiction, network firm relationship, and limited prior experience with that office. The correct answer (B) properly requires increased group engagement team involvement based on component significance and risk, including evaluation of competence and independence plus direction and review of work, consistent with PCAOB standards for supervising other auditors. Answer A incorrectly relies solely on network affiliation without considering component-specific factors. Answer C inappropriately suggests avoiding communication, when standards require active involvement. Answer D incorrectly applies AICPA standards to an issuer and misunderstands that components cannot be excluded from consolidated scope. The professional framework emphasizes risk-based involvement where component significance, complexity, and auditor familiarity drive the extent of group team procedures, with higher-risk components requiring more direct involvement including potential visits and file reviews.
Question 4
A nonissuer healthcare entity is undergoing a financial statement audit. The auditor plans to use internal audit's work on controls over patient billing adjustments; internal audit has relevant certifications (CIA) but the internal audit director's annual bonus is tied to operating margin. Internal audit's workpapers show limited evidence of supervision and inconsistent sample selection. What is the most appropriate response when evaluating the internal audit function's work?
- Increase reliance on internal audit because the CIA credential indicates strong competence, and objectivity concerns are mitigated by management oversight.
- Use internal audit's work as planned because controls testing does not require the same documentation quality as substantive testing.
- Reduce or avoid reliance on internal audit due to objectivity and quality concerns, and perform additional auditor procedures over billing adjustments. (correct answer)
- Rely on internal audit only if the internal audit director is independent under PCAOB rules for issuer engagements.
Explanation: This question tests AU-C 610 requirements for using internal audit's work when objectivity and quality concerns exist. The key facts include the internal audit director's compensation tied to operating margin (creating an objectivity threat), relevant professional certification (CIA), and documented quality issues including limited supervision and inconsistent sampling. The correct answer (C) appropriately responds to these red flags by reducing or avoiding reliance and performing additional auditor procedures, consistent with professional standards that require modification of reliance when objectivity or quality concerns exist. Answer A incorrectly prioritizes credentials over objectivity concerns and ignores documented quality issues. Answer B incorrectly suggests controls testing has lower documentation requirements than substantive testing. Answer D inappropriately applies PCAOB independence rules to a nonissuer engagement. The professional judgment framework requires auditors to holistically evaluate competence, objectivity, and work quality, with any significant deficiency in these areas warranting reduced reliance and increased auditor-performed procedures, especially for significant accounts like patient billing adjustments.
Question 5
An issuer is undergoing an integrated audit. Management uses an external actuarial specialist to measure the defined benefit pension obligation; the actuary is well-qualified but uses a discount rate derived from a proprietary model, and the obligation is highly material. The auditor plans to use the actuary's report and also notes that internal audit performed limited testing of HR data inputs used by the actuary. Which action should the auditor take when relying on a specialist's report?
- Use the actuary's report as sufficient appropriate evidence because the obligation is measured using specialized methods beyond the auditor's expertise.
- Evaluate the actuary's competence and objectivity and assess the reasonableness of significant assumptions (including the discount rate) and the underlying data, performing additional procedures as needed given the high materiality. (correct answer)
- Rely on internal audit's HR data testing to eliminate the need to test the completeness and accuracy of data provided to the actuary.
- Apply AICPA review standards and limit procedures to inquiries of the actuary about the discount rate model.
Explanation: This question tests using a management's specialist for complex pension valuations under PCAOB standards. The key facts include high materiality of the pension obligation, use of a proprietary discount rate model, qualified actuary, and limited internal audit testing of data inputs. The correct answer (B) correctly requires evaluation of competence and objectivity, assessment of significant assumptions including the proprietary discount rate, and data reliability testing with additional procedures as needed for high materiality items, consistent with AS 1210 requirements. Answer A incorrectly accepts specialist work without evaluation despite the complexity and materiality. Answer C inappropriately suggests internal audit's limited testing eliminates data testing requirements. Answer D incorrectly applies review standards to an audit engagement. The professional framework emphasizes that for highly material estimates using proprietary models, auditors must understand and test key assumptions rather than treating them as black boxes, with increased procedures proportional to materiality and estimation uncertainty, including potential use of auditor specialists to evaluate complex actuarial methods.
Question 6
A nonissuer retail company is undergoing a financial statement audit and uses a third-party service organization for payroll processing. The auditor plans to use an IT auditor to evaluate the design and implementation of user access controls over the payroll interface and to assess the complementary user-entity controls referenced in a SOC 1 Type 2 report. What criteria should the auditor consider when determining the extent of reliance on IT auditors?
- Rely on the IT auditor's conclusions without review because SOC reports eliminate the need for any user-entity control evaluation.
- Evaluate whether the IT auditor's procedures address relevant risks (including complementary user-entity controls) and whether the work is adequately documented and supervised before using it as audit evidence. (correct answer)
- Limit IT auditor procedures to inquiry because a nonissuer audit does not permit testing of IT controls.
- Require the IT auditor to be independent under PCAOB rules because payroll affects significant accounts.
Explanation: This question tests the auditor's use of IT specialists when evaluating service organization controls under AU-C 402. The key facts include a third-party payroll processor, existence of a SOC 1 Type 2 report, and the need to evaluate both user access controls and complementary user-entity controls. The correct answer (B) properly requires evaluation of whether IT auditor procedures address relevant risks including complementary controls, and assessment of documentation and supervision quality before using the work as audit evidence. Answer A incorrectly suggests SOC reports eliminate the need for user-entity control evaluation, when standards require assessment of complementary controls. Answer C incorrectly limits procedures to inquiry and misunderstands that nonissuer audits do permit IT control testing. Answer D inappropriately applies PCAOB independence rules to specialists in a nonissuer engagement. The professional framework emphasizes that service organization audits require understanding both the SOC report scope and the user entity's complementary controls, with IT specialists helping evaluate the technical aspects while the auditor maintains overall responsibility for sufficient appropriate evidence.
Question 7
A nonissuer retailer has migrated to a new cloud-based point-of-sale system midyear. The audit team plans to use an IT auditor from the firm to test general IT controls (access, change management) and automated application controls affecting sales completeness. The IT auditor is experienced with the platform but has not previously audited this client and will test only the post-migration period. What criteria should the auditor consider when determining the extent of reliance on IT auditors?
- Treat the IT auditor's work as equivalent to management's controls documentation and therefore avoid testing automated controls if substantive analytics are performed.
- Consider the IT auditor's competence and objectivity, the scope and timing of their procedures (including coverage of pre- and post-migration periods), and the significance of IT to financial reporting. (correct answer)
- Rely fully on the IT auditor's conclusions if the system is cloud-based because the service provider is responsible for IT controls.
- Rely on the IT auditor's work only if the IT auditor provides a written representation that they are independent under PCAOB rules, regardless of whether the client is a nonissuer.
Explanation: The standard being tested is AU-C Section 620, which covers using the work of an auditor's specialist, such as an IT auditor, in a nonissuer audit. Key facts include the midyear system migration, the IT auditor's experience with the platform but not the client, and testing limited to the post-migration period for IT controls affecting sales. The correct answer complies with AU-C 620 by requiring consideration of the specialist's competence, objectivity, scope, timing, and the significance of IT to financial reporting. Choice A is incorrect because IT specialist work does not substitute for control testing without evaluation; choice C is wrong as cloud-based systems still require auditor testing of relevant controls; choice D is erroneous since PCAOB independence does not apply to nonissuers and representations alone are insufficient. For transferable judgment, auditors should assess the specialist's understanding of the business, the alignment of their procedures with audit objectives, and any limitations in scope, adjusting reliance based on risk assessments and performing corroborative procedures as needed.
Question 8
A group audit is being performed for an issuer under PCAOB standards. The group engagement team plans to use the component auditor's work on a significant component but learns the component auditor used a different materiality threshold than instructed and did not communicate identified misstatements below their threshold. Based on the auditor's assessment, which factor should influence the reliance on component auditors?
- Accept the component auditor's materiality because local practice determines materiality for the component audit.
- Address the deviation by communicating required materiality and reporting thresholds, obtaining information on uncorrected misstatements, and increasing involvement or performing additional procedures as needed. (correct answer)
- Ignore the issue because misstatements below component materiality cannot affect the group financial statements.
- Apply AICPA nonissuer standards and permit the component auditor to set materiality independently without group auditor oversight.
Explanation: The concept being tested is PCAOB AS 1201, for component auditors in issuer group audits. Key facts include component auditor's deviation from instructed materiality, non-communication of misstatements. The correct answer adheres to AS 1201 by addressing deviations through communications, obtaining information, increasing involvement. Choice A is incorrect because group materiality governs; choice C is wrong as small misstatements can aggregate; choice D is erroneous since PCAOB requires oversight. For a transferable framework, auditors should enforce consistent thresholds, aggregate misstatements, and adjust procedures for deviations to maintain group assurance.
Question 9
A group audit is being performed for an issuer under PCAOB standards. The group auditor plans to use the work of a component auditor for a significant component and to assume the component auditor tested revenue controls. The component auditor's report indicates they performed a substantive-only approach and did not test controls. Based on the auditor's assessment, which factor should influence the reliance on component auditors?
- Continue to rely on component auditor work for controls because substantive testing implicitly tests controls.
- Align the group audit plan with the component auditor's actual scope; if control reliance is needed, instruct additional control testing or perform group-level procedures to address the gap. (correct answer)
- Assume controls were tested because the component auditor issued an unmodified opinion on the component financial statements.
- Apply AICPA nonissuer guidance and accept the component auditor's work without reconciling differences in audit approach.
Explanation: The concept being tested is PCAOB AS 1201, on component auditors in issuer group audits. Key facts include planned reliance on component auditor for controls, but their report shows substantive-only approach without control testing. The correct answer aligns with AS 1201 by requiring alignment of plans, additional instructions or procedures to address gaps. Choice A is incorrect because substantive testing does not test controls; choice C is wrong as opinions do not imply control testing; choice D is erroneous since PCAOB standards govern issuers. For a transferable framework, auditors should reconcile component approaches with group strategy, issue tailored instructions, and evaluate work to ensure consolidated evidence sufficiency.
Question 10
An issuer is audited under PCAOB standards. Internal audit performed substantive testing of disbursements and identified control deviations in vendor master file changes, but management remediated the control late in the year. The external auditor is considering reducing year-end substantive testing of accounts payable. What is the most appropriate response when evaluating the internal audit function's work?
- Reduce year-end substantive testing because internal audit already tested disbursements and found only control deviations, not misstatements.
- Consider the implications of identified deviations and timing of remediation, evaluate internal audit's work and perform additional procedures for the period before remediation and for residual risk at year-end. (correct answer)
- Rely on management's remediation memo as sufficient evidence that the control operated effectively for the entire year.
- Apply AICPA compilation guidance to conclude internal audit evidence is sufficient because it is internally generated.
Explanation: The concept being tested is PCAOB AS 1205, on internal auditors in issuer audits. Key facts include internal audit's deviation findings, late remediation, and planned reduction in substantive testing. The correct answer adheres to AS 1205 by requiring consideration of deviations, timing, additional procedures for periods and risks. Choice A is incorrect because deviations impact control reliance; choice C is wrong as memos are insufficient evidence; choice D is erroneous since compilation guidance is not for audits. For a transferable framework, auditors should test remediation effectiveness, assess residual risks, and link internal findings to substantive scope for comprehensive coverage.
Question 11
A nonissuer energy company is audited under AICPA standards. Management's reserve engineer (licensed, 10 years' experience) estimated proved oil and gas reserves used to support an impairment analysis; the estimate is material and highly judgmental. The engineer used a pricing deck provided by management that differs from observable forward curves. Which action should the auditor take when relying on a specialist's report?
- Use the reserve report as conclusive evidence because reserve engineering is outside the auditor's expertise.
- Evaluate the specialist's competence and objectivity and assess the reasonableness of key inputs, including comparing management's pricing deck to market data and understanding the basis for differences. (correct answer)
- Reject the specialist's work solely because the specialist is employed by management.
- Rely on the specialist only if the specialist provides a written independence confirmation under PCAOB rules applicable to issuers.
Explanation: The professional standard being tested is AU-C Section 500, for management's specialists in nonissuer audits. Key facts include the engineer's licensing and experience, use of management pricing differing from market data for material reserves estimate. The correct answer follows AU-C 500 by requiring competence and objectivity evaluation, assessment of inputs like pricing reasonableness. Choice A is incorrect because auditor expertise gaps require procedures, not blind reliance; choice C is wrong as internal specialists are allowable if assessed; choice D is erroneous since PCAOB applies to issuers. For transferable professional judgment, auditors should compare assumptions to external data, evaluate method consistency, and use sensitivity testing to judge estimate reliability.
Question 12
A nonissuer energy company is undergoing a financial statement audit. Management engaged a petroleum engineer (licensed professional engineer) to estimate proved oil and gas reserves used in the impairment analysis of long-lived assets; the engineer is also negotiating a success fee with management tied to future drilling approvals. The auditor intends to use the engineer's reserve report as audit evidence supporting impairment conclusions. Which action should the auditor take when relying on a specialist's report?
- Treat the engineer as sufficiently objective because professional licensure overrides any fee arrangement concerns.
- Use the reserve report only after evaluating the specialist's competence and objectivity (including the success-fee threat) and performing procedures to evaluate the relevance and reasonableness of key assumptions and data used. (correct answer)
- Accept the reserve report as conclusive because reserve estimation is outside the auditor's scope and cannot be tested.
- Apply PCAOB group audit requirements to determine whether the engineer qualifies as a component auditor.
Explanation: This question addresses using a management's specialist under AU-C 500 when significant objectivity threats exist. The critical facts are that the petroleum engineer has appropriate credentials (licensed PE), the reserve estimates affect impairment analysis of material assets, and the engineer has a success fee arrangement creating an objectivity threat. The correct answer (B) correctly requires evaluation of competence and objectivity including the success-fee threat, plus procedures to evaluate the relevance and reasonableness of assumptions and data, consistent with professional standards for using specialist work. Answer A incorrectly assumes professional licensure overrides objectivity concerns from fee arrangements. Answer C inappropriately suggests reserve estimates cannot be tested by auditors, when standards require evaluation of specialist work. Answer D incorrectly applies group audit requirements to a specialist engagement. The professional framework requires heightened skepticism and additional procedures when specialists have financial interests aligned with management, with the auditor performing sufficient procedures to evaluate the specialist's assumptions, methods, and conclusions rather than accepting them without scrutiny.
Question 13
A nonissuer construction company is audited under AICPA standards. Management's specialist (licensed professional engineer) provided an estimate of percentage-of-completion based on a cost-to-cost method for a material contract, including a revised estimate of total costs due to design changes. The specialist works for the company and reports to the project executive whose bonus is tied to gross margin. Which action should the auditor take when relying on a specialist's report?
- Treat the specialist as objective because engineers are subject to professional licensing requirements, and therefore accept the estimate without further testing.
- Evaluate the specialist's competence and assess threats to objectivity from reporting lines and incentives, and perform audit procedures over underlying data and significant assumptions used in the estimate. (correct answer)
- Rely on the specialist's report only if the specialist is engaged directly by the auditor rather than employed by the client.
- Reduce substantive procedures because a management's specialist estimate is considered a lower-risk assertion under AICPA standards.
Explanation: The professional standard being tested is AU-C Section 500, focusing on using management's specialists in nonissuer audits. Key facts include the specialist's licensing, employment by the client, reporting to a bonus-incentivized executive, and the material estimate involving revised costs for percentage-of-completion. The correct answer follows AU-C 500 by requiring evaluation of competence, threats to objectivity from internal ties and incentives, and procedures over data and assumptions. Choice A is incorrect because licensing does not ensure objectivity or eliminate testing; choice C is wrong as employment by the client is permissible if objectivity is assessed; choice D is erroneous since specialist involvement does not inherently lower risk or reduce procedures. For transferable professional judgment, auditors should identify objectivity threats like financial incentives or relationships, test the appropriateness of methods and assumptions, and consider alternative evidence sources when reliance is limited by bias risks.
Question 14
A nonissuer logistics company is audited under AICPA standards. The firm's IT auditor tested the interface between the transportation management system and the general ledger, including automated mapping of revenue codes. The IT auditor documented results but did not retain screenshots or system-generated reports supporting the test evidence. What criteria should the auditor consider when determining the extent of reliance on IT auditors?
- Rely on the IT auditor's conclusions because documentation detail is not required when tests relate to automated controls.
- Consider whether the IT auditor's work is adequately documented to support the nature, timing, and extent of procedures and results, and obtain additional evidence or reperform work if documentation is insufficient. (correct answer)
- Rely fully because the interface is automated and therefore not subject to error once implemented.
- Apply PCAOB documentation standards and conclude the work is unusable unless it includes sign-offs by management.
Explanation: The standard being tested is AU-C Section 620, for auditor's specialists in nonissuer audits. Key facts include IT auditor's testing of interfaces with incomplete documentation lacking supporting evidence. The correct answer complies with AU-C 620 by requiring adequate documentation evaluation, additional evidence if insufficient. Choice A is incorrect because documentation is required for all tests; choice C is wrong as automation does not exempt errors; choice D is erroneous since PCAOB standards apply to issuers. For transferable judgment, auditors should verify documentation supports conclusions, reperform if needed, and ensure alignment with audit standards for reliability.
Question 15
A nonissuer biotech company is audited under AICPA standards. Management engaged a valuation specialist to value complex share-based compensation awards with market conditions using a Monte Carlo model. The specialist is credentialed but refuses to provide the model inputs and methodology, citing proprietary restrictions, and provides only a one-page conclusion. Which action should the auditor take when relying on a specialist's report?
- Rely on the conclusion because proprietary models are common and credentials provide sufficient assurance.
- Obtain an understanding of the methods and significant assumptions and evaluate the adequacy of the specialist's work; if sufficient information cannot be obtained, perform alternative procedures or engage an auditor's specialist. (correct answer)
- Accept management's representation that the model is appropriate and treat that as a substitute for the specialist's support.
- Apply PCAOB requirements and require the specialist to be employed by the auditor, otherwise the valuation cannot be used in a nonissuer audit.
Explanation: The professional standard being tested is AU-C Section 500, on management's specialists in nonissuer audits. Key facts include specialist's credentialing, refusal to provide model details, only a brief conclusion for complex valuation. The correct answer follows AU-C 500 by requiring understanding of methods and assumptions, alternatives if information insufficient. Choice A is incorrect because credentials do not substitute transparency; choice C is wrong as representations are insufficient; choice D is erroneous since AICPA allows management's specialists. For transferable professional judgment, auditors should demand sufficient details, engage own specialists if needed, and evaluate transparency as an objectivity indicator.
Question 16
A nonissuer manufacturing company is being audited under AICPA standards. Management engaged an external valuation specialist (ASA credential, 15 years of experience) to estimate the fair value of acquired customer-relationship intangibles, which are material and involve significant unobservable inputs. The auditor notes the specialist is compensated on an hourly basis but used management-provided forecasted cash flows without independently corroborating them. Which action should the auditor take when relying on a specialist's report?
- Accept the specialist's report without further procedures because the specialist holds a recognized credential and is not paid on a contingent-fee basis.
- Evaluate the specialist's competence, capabilities, and objectivity, and perform procedures to test the significant assumptions and data (including management's forecasts) used in the valuation. (correct answer)
- Rely on the specialist's work only after obtaining a written representation from the specialist that the valuation complies with PCAOB requirements for issuer audits.
- Reduce substantive testing of the related accounts to near zero because the valuation is performed by an external specialist rather than management.
Explanation: The professional standard being tested is AU-C Section 500, which addresses the auditor's use of the work of a management's specialist in obtaining audit evidence. Key facts include the specialist's credentials, experience, hourly compensation, and use of management-provided forecasts without corroboration for a material fair value estimate with significant unobservable inputs. The correct answer aligns with AU-C 500 by requiring the auditor to evaluate the specialist's competence, capabilities, and objectivity, and to perform procedures to test significant assumptions and data, ensuring the evidence is sufficient and appropriate. Choice A is incorrect because mere credentials and fee structure do not eliminate the need for further procedures; choice C is wrong as PCAOB requirements do not apply to nonissuers and written representations alone are insufficient; choice D is erroneous because reliance on a specialist does not reduce substantive testing to near zero. For transferable professional judgment, auditors should assess the specialist's relationship with the client, the relevance of their methods to the assertion, and the reliability of data used, while considering risk factors like estimation uncertainty to determine the nature and extent of testing.
Question 17
A group audit is being performed for a nonissuer under AICPA standards. A component auditor audited a component that is not financially significant individually but contains a high-risk related-party transaction that is material to the group. The group auditor initially planned minimal involvement due to low quantitative significance. Based on the auditor's assessment, which factor should influence the reliance on component auditors?
- Keep involvement minimal because quantitative significance is the only factor in determining component auditor involvement.
- Increase involvement due to qualitative risk (material related-party transaction), including specific instructions and evaluation of the component auditor's procedures over that transaction. (correct answer)
- Exclude the related-party transaction from group audit scope because it occurred at a non-significant component.
- Apply issuer standards and automatically assume the component auditor must be referenced in the group audit report for any related-party transaction.
Explanation: The concept being tested is AU-C Section 600, for component auditors in nonissuer group audits. Key facts include component's low quantitative but high qualitative risk from material related-party transaction, initial minimal involvement plan. The correct answer follows AU-C 600 by increasing involvement for qualitative risks, with instructions and evaluations. Choice A is incorrect because qualitative factors matter; choice C is wrong as exclusions are not permitted; choice D is erroneous since AICPA applies to nonissuers. For a transferable framework, auditors should weigh quantitative and qualitative significance, tailor involvement to risks, and document rationale for reliance levels.
Question 18
A nonissuer financial services company is audited under AICPA standards. The firm's IT auditor plans to test user access reviews performed quarterly by management. However, management's review is evidenced only by an email stating "access review completed," with no listing of users reviewed or changes made. What criteria should the auditor consider when determining the extent of reliance on IT auditors?
- Rely on the control because quarterly frequency is sufficient evidence of operating effectiveness.
- Consider whether the evidence supports precision and performance of the control, and if not, expand procedures (e.g., inspect user listings, reperform the review, or test alternative controls). (correct answer)
- Conclude the control is effective because it is a management review control and therefore not dependent on documentation.
- Apply PCAOB integrated audit requirements and accept the email as sufficient because it is written documentation.
Explanation: The standard being tested is AU-C Section 620, on auditor's specialists in nonissuer audits. Key facts include IT auditor's testing of access reviews with inadequate email-only evidence lacking details. The correct answer complies with AU-C 620 by requiring evidence evaluation for precision, expansions if insufficient. Choice A is incorrect because frequency does not substitute evidence; choice C is wrong as documentation is needed for reviews; choice D is erroneous since PCAOB is for issuers. For transferable judgment, auditors should ensure evidence demonstrates performance, test alternatives if gaps exist, and adjust reliance based on control precision.
Question 19
A group audit is being performed for a nonissuer under AICPA standards. The group auditor intends to assume responsibility for the component auditor's work. The component auditor is competent, but their audit documentation is in a language the group team cannot read, and translations would be costly. Based on the auditor's assessment, which factor should influence the reliance on component auditors?
- Assume responsibility without reviewing documentation because cost considerations justify limiting involvement.
- Ensure the group auditor can evaluate the component auditor's work (e.g., through translated key workpapers or bilingual reviewers) and increase involvement or perform additional procedures if evaluation is not feasible. (correct answer)
- Make reference to the component auditor in the group audit report to avoid any need to understand their documentation.
- Apply PCAOB rules and conclude that documentation language is irrelevant if the component auditor is licensed.
Explanation: The concept being tested is AU-C Section 600, for component auditors in nonissuer group audits. Key facts include intent to assume responsibility, component auditor's unreadable documentation language, costly translations. The correct answer follows AU-C 600 by requiring evaluation feasibility, alternatives if not. Choice A is incorrect because evaluation requires review; choice C is wrong as reference avoids assumption; choice D is erroneous since language impacts evaluation. For a transferable framework, auditors should plan for access barriers, use bilingual resources, and choose reference over assumption if evaluation impossible.
Question 20
An external auditor is assessing the internal audit function of a nonissuer client to determine the extent to which the internal auditors' work can be used. Which of the following factors is most critical when evaluating the internal audit function's objectivity?
- The professional certifications and technical training of the internal audit staff.
- The systematic and disciplined approach used by the internal audit function, including its quality control policies.
- The organizational status of the internal audit function and the reporting lines of the chief audit executive. (correct answer)
- The scope of the internal audit function's planned work for the period under audit.
Explanation: Objectivity relates to the internal auditors' ability to perform their tasks impartially. The most critical factor for objectivity is the organizational status of the internal audit function, specifically who they report to. Reporting to those charged with governance (e.g., the audit committee) rather than to management enhances objectivity by reducing potential conflicts of interest and pressure from management.