Home › Certifications › CPA AUD › Risk assessment
60 multiple-choice questions and 51 flashcards on Risk assessment, about 15% of the CPA AUD bank. Every one carries a written rationale.
Risk assessment is one of 6 chapters in CoStudy's CPA — Auditing & Attestation (AUD) [Core] bank, and it holds 60 of the bank's 410 multiple-choice questions — roughly 15% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
Which of the following would LEAST likely cause a firm to decline continuance of an existing audit client?
Answer: C — The client requests that fieldwork begin two weeks earlier than in the prior year
A), B), and D) each represent substantive integrity, independence, or relationship concerns that would appropriately trigger reconsideration of continuance. C) Correct as the exception — a scheduling request to start fieldwork earlier is an operational/logistics matter with no bearing on integrity, independence, or the firm's ability to serve the client appropriately.
A risk factor by itself, without other corroborating conditions, is BEST understood as:
Answer: D — something that indicates a heightened possibility fraud may exist, but not by itself proof that fraud exists
A) No single risk factor is conclusive proof of fraud on its own. C) Risk factors remain relevant to risk assessment even absent any admission by management. B) A single risk factor does not automatically drive an adverse opinion; opinion modifications depend on the actual audit findings. D) Correct — fraud risk factors are conditions that indicate an incentive/pressure, opportunity, or attitude that may increase the possibility of fraud, but their presence alone does not establish that fraud has actually occurred.
Before accepting a new audit engagement, the successor auditor should:
Answer: D — Attempt to communicate with the predecessor auditor
D) Correct — AU-C 210 requires the successor to inquire of the predecessor about disagreements, integrity, and reasons for change (with client consent). B) Waiting does not satisfy acceptance procedures. C) Substantive testing occurs during the audit, not before acceptance. A) There is no preliminary opinion issued before acceptance.
The audit risk model is expressed as:
Answer: C — AR = IR × CR × DR (three risks multiplied)
A) The components combine multiplicatively, not additively. C) Correct — AR = IR × CR × DR; the auditor accepts a low AR, assesses IR and CR (their product is RMM), and sets DR through the nature/timing/extent of procedures. B) RMM equals IR × CR; dividing does not describe the model. D) Control risk is a required component of RMM.
An auditor identifies a significant risk related to an unusual, one-time related-party transaction recorded near year-end. Which response is MOST appropriate?
Answer: A — Perform procedures specific to the transaction, such as examining its terms, corroborating the business rationale, and evaluating proper authorization, beyond routine substantive testing
B) Routine analytics designed for recurring transactions are not tailored to detect risks associated with unusual, judgmental, near-year-end related-party transactions. C) The non-recurring nature of a transaction does not reduce the need for scrutiny — unusual transactions warrant more, not less, testing due to elevated risk. D) Deferring testing to the following year is inconsistent with the auditor's responsibility to obtain sufficient evidence about the current period's financial statements before reporting. A) Correct — this reflects a response tailored to the specific risk characteristics of the transaction.
In evaluating whether to accept a new audit client, which of the following is the auditor's PRIMARY consideration regarding management's integrity?
Answer: C — Obtaining information about the identity, business reputation, and integrity of the entity's principal owners, key management, and those charged with governance, including inquiry of the predecessor auditor where applicable
A) Consistently meeting earnings estimates is not, by itself, an indicator of management integrity and could even signal earnings management concerns. B) Industry risk level is a separate consideration from management integrity, though both factor into overall client acceptance risk. D) Fee willingness has no bearing on management's integrity. C) Correct — this reflects the required focus of the integrity assessment during client acceptance.
A client's revenue is highly concentrated in the last two weeks of each fiscal quarter, with a pattern of large, unusual sales followed by high return rates early in the next quarter. This pattern is MOST likely to increase the auditor's assessment of:
Answer: B — Fraud risk related to premature or fictitious revenue recognition to meet earnings targets
A) Depreciation estimates are unrelated to the described sales/returns pattern. B) Correct — a spike in sales near period-end followed by unusually high subsequent returns is a classic indicator of channel stuffing or premature revenue recognition intended to meet targets, heightening fraud risk in revenue. C) The facts describe a revenue and sales pattern, not payroll processing controls. D) Detection risk is a function of the auditor's own procedures; the client pattern raises inherent and fraud risk, which the auditor addresses by adjusting planned procedures.
In a first-year audit, the successor auditor's incremental procedures typically include:
Answer: B — Reading prior-period financials and predecessor workpapers
A) The successor does not reissue the predecessor's opinion. B) Correct — AU-C 510 requires the successor to obtain sufficient appropriate evidence about opening balances, often by reading prior statements and reviewing predecessor workpapers with client consent. C) Full re-audit from inception is not required. D) The current opinion does not replace prior-period opinions.
Journal-entry testing in response to the management-override risk typically targets:
Answer: C — Entries with unusual characteristics or timing
A) Timing-based limits are not the criterion. B) Automated entries are lower risk than manual override. C) Correct — the auditor targets entries with unusual accounts, round amounts, late-period timing, or other override red flags. D) Immaterial entries are generally out of scope.
In the audit risk model, the risk that the auditor can most directly influence is:
Answer: A — Detection risk
D) Inherent risk depends on the nature of the account. B) Control risk depends on the client's controls. C) Business risk is a client attribute. A) Correct — detection risk is set by the auditor through the nature, timing, and extent of procedures; the other components are properties of the client.
4 cards from the 51 in this chapter.
Name the core SQMS 1 acceptance/continuance factors.
Integrity and ethical values of the client (management/TCWG); the firm's competence, capability, time, and resources; and the firm's ability to comply with relevant ethical requirements, including independence.
Component materiality in a group audit?
Set lower than group materiality to reduce the risk that aggregated uncorrected/undetected misstatements across components become material.
Fraudulent financial reporting?
Intentional misstatement to deceive users. Common: revenue manipulation.
Give an example of an 'incentive/pressure' fraud risk factor.
Financial stability threatened by declining margins or industry conditions, or management compensation tied to aggressive earnings targets.
These are a sample. The full Risk assessment chapter runs 111 items with per-chapter progress tracking, on the web and in the iOS app.