CoStudy

HomeCertificationsCPA AUD › Reporting

Reporting — CPA AUD practice questions

129 multiple-choice questions and 111 flashcards on Reporting, about 31% of the CPA AUD bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Reporting is one of 6 chapters in CoStudy's CPA — Auditing & Attestation (AUD) [Core] bank, and it holds 129 of the bank's 410 multiple-choice questions — roughly 31% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Reporting practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

A client prepares financial statements on the regulatory basis of accounting solely to comply with a state insurance regulator's requirements, and the report is intended for general use as well. Under AU-C 800, how should the auditor MOST appropriately report?

  1. Issue a standard unmodified GAAP-basis report without any reference to the regulatory framework
  2. Include an other-matter paragraph restricting the use of the report to the regulatory agency and management only, since general use is never permitted for regulatory-basis statements
  3. Report using the special purpose framework reporting requirements applicable to regulatory bases intended for general use, which do not require a restricted-use paragraph (unlike a regulatory basis intended only for limited use)
  4. Decline to issue any report, since regulatory-basis financial statements can never be used for general distribution

Answer: C — Report using the special purpose framework reporting requirements applicable to regulatory bases intended for general use, which do not require a restricted-use paragraph (unlike a regulatory basis intended only for limited use)

A) Reporting as if the statements were GAAP-basis, without acknowledging the special purpose framework, misrepresents the actual basis of accounting used. B) A restricted-use paragraph is required for regulatory-basis statements intended solely for filing with the regulator (limited use), not when the regulatory basis is intended for general use as stated in this fact pattern. D) Declining to report is incorrect; AU-C 800 specifically addresses how to report on regulatory-basis statements intended for general use. C) Correct — AU-C 800 distinguishes regulatory-basis financial statements intended for general use (no restriction required) from those intended solely for filing with the regulator (restricted use required).

An agreed-upon procedures (AUP) engagement under SSAE results in:

  1. An opinion on the subject matter under review
  2. A limited-assurance conclusion on the subject matter
  3. A report of findings from the specified procedures
  4. A compilation of the client's financial statements

Answer: C — A report of findings from the specified procedures

A) AUP engagements do not express an opinion. C) Correct — under SSAE 19, an AUP engagement reports the findings from the procedures agreed with the engaging party; users take responsibility for procedure sufficiency. B) AUP is not a limited-assurance engagement. D) AUP is not a compilation.

A predecessor auditor is asked to reissue its report on prior-period financial statements for inclusion in comparative statements. 'Reissuing' the report, as opposed to 'updating' it, means the predecessor:

  1. uses the original report date and does not reflect information discovered after that date
  2. performs a full re-audit of the prior period before reissuance
  3. automatically incorporates the successor's current-year findings into the reissued opinion
  4. must change the opinion type to match the successor's current-year opinion

Answer: A — uses the original report date and does not reflect information discovered after that date

B) A full re-audit is not required merely to reissue a previously issued report. C) The successor's current-year findings are a separate matter and are not automatically folded into the predecessor's reissued report. D) The reissued opinion reflects conditions as of the original date, not a forced match to the successor's current opinion. A) Correct — reissuing uses the same report date as originally issued and does not incorporate events or information arising after that date, unlike updating, which reflects the auditor's knowledge as of a later date.

Regarding independence, an AUP engagement performed under AT-C 215 GENERALLY requires the practitioner to:

  1. be independent of the responsible party, consistent with general attestation requirements
  2. have no independence requirement whatsoever since no opinion is expressed
  3. be independent only if the engaging party is an SEC issuer
  4. disclose a lack of independence only if requested by the engaging party

Answer: A — be independent of the responsible party, consistent with general attestation requirements

B) Independence is still generally required even though no opinion or conclusion is expressed; findings-based reporting still carries an independence expectation. C) The independence expectation is not limited to SEC issuers; it applies more broadly under the attestation standards. D) Independence isn't merely optional-disclosure based; it's a baseline requirement, with only limited circumstances allowing disclosed non-independence. A) Correct — AT-C 215 generally requires the practitioner to be independent, consistent with the broader attestation standards framework, though certain frameworks permit performing the engagement with disclosed lack of independence in limited circumstances.

Under SOX, the audit committee of an SEC issuer is responsible for:

  1. Appointing and overseeing the external auditor
  2. Selecting the client's outside legal counsel
  3. Preparing the client's financial statements
  4. Setting the CEO's annual bonus compensation

Answer: A — Appointing and overseeing the external auditor

C) Statement preparation is a management responsibility. B) Legal-counsel selection is not the committee's SOX role. A) Correct — SOX §301 requires the audit committee to appoint, compensate, and oversee the external auditor. D) CEO compensation is typically the compensation committee's role.

Which of the following is required to be communicated in writing, rather than only orally, to those charged with governance under the auditing standards for nonissuers, absent limited exceptions?

  1. Preliminary discussions about audit timing and staffing
  2. Informal observations about accounting personnel workload during the busy season
  3. Significant deficiencies and material weaknesses in internal control identified during the audit
  4. General industry trends discussed during the planning meeting

Answer: C — Significant deficiencies and material weaknesses in internal control identified during the audit

A) Preliminary scheduling and staffing discussions are typically handled through ordinary planning communications and are not subject to a written-communication mandate. B) Informal workload observations are not a matter requiring written communication. D) General industry trend discussions during planning are informational and not subject to a written-communication requirement. C) Correct — significant deficiencies and material weaknesses in internal control must generally be communicated in writing to those charged with governance.

Under Uniform Guidance, a 'major program' is determined using a:

  1. Fixed percentage of all federal expenditures
  2. Risk-based approach considering multiple factors
  3. Random selection from all federal programs
  4. Client-designated selection from prior audits

Answer: B — Risk-based approach considering multiple factors

A) A fixed percentage is not the trigger. C) Selection is not random. B) Correct — Uniform Guidance uses a risk-based approach considering program size, complexity, and prior deficiencies to identify major programs. D) The client cannot self-select major programs.

An auditee receives federal awards under two related federal programs that share common compliance requirements and are designated by OMB as a 'cluster of programs.' For single audit major program determination purposes, this cluster is treated:

  1. As entirely separate and unrelated programs, evaluated for major program status independently of one another
  2. As one program, with expenditures aggregated across both programs comprising the cluster when applying dollar thresholds and risk assessment for major program determination
  3. As excluded entirely from the single audit scope, since clusters are addressed under a separate audit standard
  4. As major only if each individual program within the cluster independently exceeds the dollar threshold

Answer: D — As major only if each individual program within the cluster independently exceeds the dollar threshold

A) Treating cluster programs as entirely separate contradicts the Uniform Guidance's specific instruction to treat a cluster as one program. C) Clusters are not excluded from single audit scope; they remain squarely within the Uniform Guidance's compliance audit requirements, just aggregated for determination purposes. D) Requiring each individual program within the cluster to independently exceed the threshold misapplies the aggregation rule; the whole point of cluster treatment is to combine expenditures rather than evaluate components separately. B) Correct — the Uniform Guidance requires that a cluster of programs be treated as one program for purposes of applying dollar thresholds and risk-based major program determination.

The difference between an adverse and a qualified opinion turns on whether the misstatement is:

  1. Material and pervasive, versus material but not pervasive
  2. Discovered before or after the report date
  3. Identified by internal audit or by external audit
  4. Corrected by management or left uncorrected

Answer: A — Material and pervasive, versus material but not pervasive

B) Discovery timing does not drive opinion type. A) Correct — under AU-C 705, an adverse opinion is issued when the misstatement is material AND pervasive; a qualified opinion is issued when it is material but not pervasive. C) The source of identification does not drive it. D) Correction eliminates the misstatement, so the choice does not arise.

An auditor wishes to indicate in the current-year report that the prior-year financial statements were audited by a predecessor auditor whose report is not being reissued. Which reporting mechanism is appropriate?

  1. An emphasis-of-matter paragraph
  2. An other-matter paragraph identifying that the prior-year statements were audited by a predecessor, along with the type of opinion and its date
  3. A qualification of the current-year opinion
  4. A note disclosure only, with no reference in the auditor's report

Answer: B — An other-matter paragraph identifying that the prior-year statements were audited by a predecessor, along with the type of opinion and its date

A) Emphasis-of-matter paragraphs address matters already presented or disclosed within the financial statements — reference to the predecessor's report is a matter about the audit itself, not the financial statements. C) The current opinion is not qualified merely because a predecessor audited the prior period. D) Auditing standards require this reference to appear in the auditor's report, not merely in a client note. B) Correct — this is a classic other-matter paragraph use case.

Reporting flashcards

4 cards from the 111 in this chapter.

Updating vs. reissuing a predecessor's report on comparative statements — key difference?

Updating expresses a current opinion in light of new information as of the current report date; reissuing uses the original report date and does not reflect later-discovered information.

What is a complementary user entity control (CUEC)?

A control that the service organization's system description assumes will be implemented by user entities, and which is necessary to achieve the control objectives described in a SOC 1 report.

Uniform Guidance single audit — how are major programs determined?

Through a risk-based approach combining dollar thresholds with program-specific inherent risk factors — not simply the largest programs by dollar amount.

Audit report dating?

No earlier than date sufficient appropriate evidence obtained AND F/S approved by management.

Practise the full chapter

These are a sample. The full Reporting chapter runs 240 items with per-chapter progress tracking, on the web and in the iOS app.

Open CPA AUD in CoStudy →

Other CPA AUD chapters

All CPA AUD practice questions →