A self-paced introduction to Auditing covering the audit process and professional standards: PCAOB and AICPA GAAS, ethics and independence, client acceptance and planning, the audit risk model, the COSO internal-control framework, audit evidence and procedures, sampling, fraud considerations, completion and subsequent events, and audit reporting (unmodified, qualified, adverse, disclaimer). Includes 10 video lectures with ~3-page printable notes each, 10 class exercises (100 questions), three tests (20 questions each), one 40-question final exam, and a six-phase mini-audit engagement capstone.
An AUDIT is a systematic process of objectively obtaining and evaluating evidence about assertions regarding economic actions and events, to ascertain the degree of correspondence between those assertions and established criteria, and communicating the results to interested users. In a financial-statement audit, management makes assertions in the form of financial statements (that assets exist, that revenues are complete, that liabilities are properly valued), the auditor gathers evidence to test those assertions against the applicable framework (U.S. GAAP or IFRS), and issues an opinion. The audit exists because of an information asymmetry: users of financial statements (investors, lenders, regulators) do not have access to the underlying books, and they need a competent, INDEPENDENT professional to reduce information risk — the risk that the information they rely on is materially misstated.
Auditing is one member of a broader family of ASSURANCE SERVICES. Assurance is any independent professional service that improves the quality of information for decision-makers. Financial-statement audits are the flagship assurance service, but the profession also performs reviews (limited assurance, e.g., an SSARS review for a private company), agreed-upon procedures engagements (no opinion — only findings), compilations (no assurance), and specialized attestations over sustainability reports (ISSB S1/S2), internal control (SOX 404(b) for accelerated filers), and service organization controls (SOC 1 and SOC 2). Understanding this taxonomy is essential: exam questions and clients frequently ask what service they need, and each service has its own report, standards, and level of assurance.
Who performs audits and under what rules depends on the client. Audits of U.S. PUBLIC companies (those whose securities trade on a U.S. exchange) must be performed by a registered CPA firm under PCAOB Auditing Standards — the Sarbanes-Oxley Act of 2002 created the PCAOB and stripped standard-setting for public-company audits from the AICPA. Audits of PRIVATE U.S. companies are performed by CPA firms under the AICPA's Statements on Auditing Standards (SAS), codified as the clarified AU-C sections. International audits follow the International Standards on Auditing (ISA) issued by the IAASB. In every case, the auditor must be independent in both fact and appearance, exercise professional skepticism, use professional judgment, and comply with a body of ethics — the AICPA Code of Professional Conduct in the U.S., the IESBA Code internationally.
Auditors work under a body of professional standards that answers three questions: HOW should the auditor behave (ethics), HOW should the audit be performed (auditing standards), and WHAT should the auditor report (reporting standards). Generally Accepted Auditing Standards (GAAS) — historically ten in number, now embedded in the clarified AU-C sections and PCAOB AS 1000 series — organize into three groups: (1) GENERAL standards (adequate training and proficiency, independence in mental attitude, due professional care), (2) FIELDWORK standards (adequate planning and supervision, understanding the entity and its environment including internal control, sufficient appropriate audit evidence), and (3) REPORTING standards (statements presented in accordance with GAAP, consistency, disclosure adequate, express an opinion). The AU-C 200 series and PCAOB AS 1000/1005 codify these expectations for private and public audits respectively.
INDEPENDENCE is the auditor's most valuable asset and the single most tested topic on the CPA exam. Independence must be maintained BOTH IN FACT (an objective state of mind) AND IN APPEARANCE (nothing that a reasonable third party would view as impairing objectivity). The AICPA Code applies a THREATS AND SAFEGUARDS conceptual framework: identify the threat (self-review, advocacy, familiarity, self-interest, undue influence, management participation), evaluate its significance, and apply safeguards to reduce it to an acceptable level. The SEC and PCAOB overlay stricter rules for public-company auditors: prohibited non-audit services (bookkeeping, financial-information-systems design, valuation, actuarial for insurance, internal audit outsourcing, HR, broker-dealer, legal, expert services), audit partner rotation every 5 years, and a one-year cooling-off period before a former audit team member can take a key financial-reporting role at the client.
The AICPA Code of Professional Conduct is organized around six PRINCIPLES: Responsibilities, the Public Interest, Integrity, Objectivity and Independence, Due Care, and Scope and Nature of Services. Beneath the principles sit enforceable RULES for members in public practice (independence, integrity and objectivity, general standards, compliance with standards, accounting principles, acts discreditable, contingent fees, commissions and referral fees, advertising, confidential information, form of organization and name). Contingent fees and commissions are broadly prohibited for attest clients; confidentiality prohibits disclosing client information without consent, except for specific circumstances (quality review, subpoena, PCAOB inspection, changes of auditor). Violations can result in loss of AICPA membership, loss of CPA license, monetary penalties, and — for public company auditors — sanctions from the PCAOB and SEC.
Before an audit begins, the firm performs CLIENT ACCEPTANCE (for new clients) or CLIENT CONTINUANCE (for recurring clients). The firm evaluates management integrity (background searches, reference checks, communication with the predecessor auditor), the risk profile of the industry and entity, the firm's independence and competence to serve the client, and the client's ability to pay. AU-C 210 / ISA 210 require the auditor to communicate with the PREDECESSOR AUDITOR — with the prospective client's permission — to ask about disagreements, management integrity, and reasons for the change. If permission is refused, that is itself a red flag. Once accepted, the auditor and the client sign an ENGAGEMENT LETTER that documents the scope, the responsibilities of management (preparing the statements, designing controls, providing access), the responsibilities of the auditor (expressing an opinion in accordance with GAAS/PCAOB standards), the framework (GAAP), the reporting form, and fees. The engagement letter is a contract; issuing it is the acceptance step.
PLANNING then structures the audit so it can be performed effectively and efficiently. Required activities under AU-C 300 / AS 2101 include: developing an overall AUDIT STRATEGY (scope, timing, direction), documenting a DETAILED AUDIT PLAN (nature, timing, and extent of risk-assessment procedures and further audit procedures), assembling the ENGAGEMENT TEAM (with the right skills for the client's industry and complexity), scheduling communications with those charged with governance, and coordinating with internal auditors, component auditors, and specialists (valuation experts, IT auditors, actuaries). Planning is not a one-time event — the plan is continuously revised as new information is obtained during the audit.
MATERIALITY is the auditor's judgment about the smallest misstatement that could influence a user's decision. The auditor sets OVERALL materiality (usually a percentage of a benchmark such as 5% of pre-tax income, 0.5% of revenue, or 1% of total assets), then a lower PERFORMANCE MATERIALITY (typically 50-75% of overall) that is used to design and perform procedures — it provides a margin so that individually immaterial misstatements do not aggregate to a material total. A still lower CLEARLY TRIVIAL threshold (often 5% of overall materiality) allows the auditor to disregard tiny findings. Materiality has two dimensions: QUANTITATIVE (the dollar amount) and QUALITATIVE (nature of the item — related-party transactions, illegal acts, misstatements that turn a loss into a profit, or that affect trends and ratios are material regardless of size). Materiality is revisited throughout the audit as more information becomes available.
The AUDIT RISK MODEL states that AUDIT RISK (AR) — the risk that the auditor issues an unmodified opinion when the statements are materially misstated — equals the product of three components: INHERENT RISK (IR), the susceptibility of an assertion to material misstatement before considering controls; CONTROL RISK (CR), the risk that a material misstatement is not prevented or detected on a timely basis by internal control; and DETECTION RISK (DR), the risk that the auditor's procedures fail to detect a material misstatement that exists. Algebraically, AR = IR × CR × DR, so DR = AR / (IR × CR). Auditors set the desired AR (typically 5%), assess IR and CR based on the entity, and then design substantive procedures whose extent, nature, and timing reduce DR to the level required. Higher inherent or control risk (say, a cash-intensive retailer with weak segregation of duties) forces a lower detection risk, which means more evidence, more experienced staff, and testing closer to year-end.
The RISK OF MATERIAL MISSTATEMENT (RMM = IR × CR) is assessed at both the FINANCIAL STATEMENT level (pervasive risks such as going concern, management override, and a weak control environment) and the ASSERTION level (specific risks tied to specific accounts and assertions: e.g., existence of inventory, valuation of receivables, completeness of accrued liabilities). At the assertion level, the auditor thinks about EACH management assertion — for transactions and events: Occurrence, Completeness, Accuracy, Cutoff, Classification, Presentation; for balances at period-end: Existence, Rights & Obligations, Completeness, Valuation & Allocation; and for presentation and disclosure: Occurrence & Rights, Completeness, Accuracy & Valuation, Classification & Understandability. This assertion-based thinking connects risk assessment to the design of procedures.
RISK-ASSESSMENT PROCEDURES include INQUIRY of management and others, OBSERVATION of operations and controls in action, INSPECTION of documents (organization chart, meeting minutes, prior-year workpapers), and ANALYTICAL PROCEDURES that identify unusual relationships. The auditor also gathers an UNDERSTANDING OF THE ENTITY AND ITS ENVIRONMENT under AU-C 315 / AS 2110: industry, regulatory, and other external factors; the entity's operations, ownership, and structure; its accounting policies; its objectives, strategies, and business risks; and the measurement and review of its financial performance. Only after this understanding is complete can the auditor identify SIGNIFICANT RISKS — risks that require special audit consideration (often revenue recognition, management override, related parties, non-routine transactions, and significant judgments). Significant risks demand a substantive procedure specifically designed for them; the auditor cannot rely solely on tests of controls.
INTERNAL CONTROL is a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in three categories: OPERATIONS (efficiency, effectiveness), REPORTING (reliability of internal and external reporting), and COMPLIANCE (with laws and regulations). The auditor is primarily concerned with controls over FINANCIAL REPORTING (ICFR). The COSO 2013 framework organizes internal control into FIVE INTEGRATED COMPONENTS: (1) CONTROL ENVIRONMENT — the tone at the top, board oversight, integrity and ethics, competence, structure; (2) RISK ASSESSMENT — how the entity identifies and analyzes risks to objectives; (3) CONTROL ACTIVITIES — the policies and procedures that mitigate risks (authorizations, reconciliations, segregation of duties, IT general controls); (4) INFORMATION & COMMUNICATION — how information flows internally and externally; and (5) MONITORING ACTIVITIES — ongoing and separate evaluations that assess whether controls are still working. Beneath the five components sit 17 PRINCIPLES that must all be present, functioning, and integrated for the system to be effective.
The auditor must OBTAIN AN UNDERSTANDING of all five components sufficient to identify and assess risks of material misstatement, whether or not the auditor plans to rely on controls. Documentation techniques include NARRATIVES (written descriptions of a process), FLOWCHARTS (visual depictions of transaction flows), and INTERNAL CONTROL QUESTIONNAIRES. A WALK-THROUGH — tracing one transaction from initiation to inclusion in the financial statements — is required for public-company audits and strongly recommended for private-company audits; it confirms that documented controls are actually in place. If the auditor plans to RELY on controls (to reduce the extent of substantive procedures), TESTS OF CONTROLS are required to gather evidence that the controls operated effectively throughout the period. Tests include inquiry combined with inspection, observation, reperformance, or a combination.
The auditor must communicate control deficiencies to management and those charged with governance. Deficiencies come in three severity tiers: a DEFICIENCY (control missing or not operating), a SIGNIFICANT DEFICIENCY (important enough to merit attention by those charged with governance), and a MATERIAL WEAKNESS (a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis). MATERIAL WEAKNESSES in ICFR trigger an ADVERSE opinion on internal control under SOX 404(b) for accelerated filers and must be disclosed in the 10-K. The client's remediation is monitored in subsequent periods. For non-accelerated filers, only management's report on ICFR is required (SOX 404(a)); the auditor does not issue an ICFR opinion but must still consider controls when planning the financial-statement audit.
AUDIT EVIDENCE is information used by the auditor to arrive at conclusions on which the audit opinion is based. Evidence must be both SUFFICIENT (quantity — enough to support the conclusion) and APPROPRIATE (quality — relevant and reliable for the assertion being tested). Relevance means the evidence relates to the assertion at issue (a bank confirmation is highly relevant for the existence of cash; it is not relevant for the completeness of accounts payable). Reliability is a function of source and nature: externally sourced evidence (confirmations from third parties) is more reliable than internally generated evidence; documentary evidence is more reliable than oral; original documents are more reliable than photocopies; evidence obtained directly by the auditor is more reliable than evidence obtained from the entity. As the risk of material misstatement increases, more sufficient and more appropriate evidence is required.
AUDIT PROCEDURES generate evidence. The seven basic procedures — memorized as a checklist — are (1) INSPECTION of records or documents (voucher a purchase to invoice), (2) INSPECTION of tangible assets (count inventory, examine fixed assets), (3) OBSERVATION (watch the inventory count team perform the procedure), (4) EXTERNAL CONFIRMATION (send a positive or negative confirmation to a customer, bank, attorney), (5) RECALCULATION (recompute depreciation, extend inventory quantities × cost), (6) REPERFORMANCE (independently execute a control such as a bank reconciliation), and (7) ANALYTICAL PROCEDURES (compare current-period ratios to prior periods, budgets, or industry). INQUIRY of client personnel is almost always used but, by itself, produces the least reliable evidence — it must be corroborated by another procedure. Procedures are further classified as TESTS OF CONTROLS (assess whether controls operate effectively) or SUBSTANTIVE PROCEDURES (detect material misstatements directly, either via tests of details or substantive analytical procedures).
The auditor documents evidence in AUDIT WORKPAPERS (or 'audit documentation') that are the property of the audit firm but are protected by client confidentiality. Documentation must be sufficient for an experienced auditor with no previous connection to the engagement to understand the nature, timing, and extent of procedures performed, the results and evidence obtained, significant findings and conclusions, and the identities of who performed and reviewed the work. For public-company audits, the DOCUMENTATION COMPLETION DATE is 45 days after the report release date (60 days for private audits under AU-C 230), and documentation must be RETAINED for 7 years (SOX / PCAOB AS 1215). After the completion date, documentation may not be deleted or removed — only added to with proper explanation.
AUDIT SAMPLING is the application of an audit procedure to less than 100% of the items within an account balance or class of transactions for the purpose of drawing a conclusion about the whole population. Two broad categories exist: STATISTICAL SAMPLING (uses probability theory to measure sampling risk and project results) and NONSTATISTICAL (JUDGMENTAL) SAMPLING (relies on the auditor's judgment). Both are permitted under GAAS, and both must adequately consider sampling risk — the risk that the sample is not representative of the population. Sampling risk has two flavors depending on the test: for TESTS OF CONTROLS, the risk of ASSESSING CONTROL RISK TOO LOW (efficiency-affecting, harmful to the audit — auditor over-relies on a weak control) versus TOO HIGH (efficiency-affecting, wastes work); for SUBSTANTIVE TESTS, the risk of INCORRECT ACCEPTANCE (effectiveness-affecting — auditor concludes an account is fairly stated when it is materially misstated) versus INCORRECT REJECTION (efficiency-affecting).
ATTRIBUTE SAMPLING is used in TESTS OF CONTROLS to estimate the RATE OF DEVIATION from a prescribed control (e.g., 'what percentage of purchase orders lack the required approval signature?'). Sample size is driven by (a) the TOLERABLE DEVIATION RATE (the maximum rate the auditor can accept and still rely on the control), (b) the EXPECTED POPULATION DEVIATION RATE (auditor's expectation based on prior experience), and (c) the DESIRED CONFIDENCE LEVEL (typically 90-95%). If the sample deviation rate plus a computed allowance for sampling risk (the UPPER DEVIATION RATE) is LESS THAN the tolerable deviation rate, the auditor can rely on the control. Otherwise, control risk is assessed higher and substantive procedures are increased.
VARIABLES (or MONETARY UNIT) SAMPLING is used in SUBSTANTIVE TESTS OF DETAILS to estimate the DOLLAR AMOUNT of misstatement in a population. Common techniques include CLASSICAL VARIABLES SAMPLING (mean-per-unit, ratio, difference estimation — best when misstatements are frequent and both over- and understatements are expected) and MONETARY UNIT SAMPLING (MUS or PPS) which selects items with probability proportional to their dollar size — larger items are more likely to be selected. MUS is efficient when overstatement is the concern (accounts receivable, inventory valuation) and expected misstatements are few. The auditor projects a MOST LIKELY MISSTATEMENT and adds an ALLOWANCE FOR SAMPLING RISK to obtain an UPPER MISSTATEMENT LIMIT. If that limit exceeds TOLERABLE MISSTATEMENT (a component of performance materiality), the account is not accepted as fairly stated and further procedures — or an adjustment — is required.
AU-C 240 / ISA 240 / PCAOB AS 2401 govern the auditor's responsibilities relating to FRAUD in a financial-statement audit. Fraud is an INTENTIONAL act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage. The standard distinguishes two types: FRAUDULENT FINANCIAL REPORTING (management misstates the statements to mislead users — Enron, WorldCom, Wirecard) and MISAPPROPRIATION OF ASSETS (employee theft — often small individual amounts that aggregate). The auditor is responsible for obtaining reasonable assurance that the statements are free from material misstatement, whether caused by ERROR or FRAUD. Management is responsible for prevention and detection. The auditor's higher duty is to apply PROFESSIONAL SKEPTICISM — a questioning mind and a critical assessment of audit evidence — throughout the engagement.
The FRAUD TRIANGLE (Cressey) explains when fraud occurs: (1) INCENTIVE / PRESSURE (financial pressure, aggressive earnings targets, personal debt), (2) OPPORTUNITY (weak controls, override potential, lack of segregation of duties), and (3) RATIONALIZATION (the perpetrator's attitude that the act is justified — 'the company owes me' or 'I'll pay it back'). The auditor is required to hold a FRAUD BRAINSTORMING SESSION with the engagement team at the planning stage to discuss where and how fraud could occur; make INQUIRIES of management, those charged with governance, internal audit, and others about known or suspected fraud; assess REVENUE RECOGNITION as a PRESUMED SIGNIFICANT FRAUD RISK unless the presumption is rebutted; and specifically address the RISK OF MANAGEMENT OVERRIDE OF CONTROLS — which is present in every audit and cannot be rebutted. Management override procedures include testing journal entries (especially at period-end), reviewing significant accounting estimates for bias, and evaluating the business rationale of significant unusual transactions.
If the auditor identifies a MISSTATEMENT that MAY BE THE RESULT OF FRAUD, the auditor must consider its implications for other aspects of the audit (particularly management representations), discuss it with an appropriate level of management at least one level above those involved, and — for fraud involving senior management or material fraud — communicate promptly with those charged with governance. When the auditor concludes that continuing the engagement is not possible (e.g., management's integrity is called into question), the auditor may WITHDRAW, communicating the reasons to those charged with governance and, in some jurisdictions, to regulators. Under Section 10A of the Securities Exchange Act, U.S. public-company auditors must report certain illegal acts to the SEC if management or the audit committee fails to take timely remedial action. Failure to detect fraud is not itself an audit failure; failure to APPLY GAAS with due skepticism IS.
The COMPLETION PHASE consolidates the auditor's work and drives the opinion. Key procedures include (1) SUBSEQUENT-EVENT REVIEW under AU-C 560, distinguishing TYPE I (recognized) subsequent events — conditions that existed at the balance-sheet date and are now clarified (e.g., customer bankruptcy in January revealing that Dec 31 receivable was uncollectible) — from TYPE II (nonrecognized) events that arose AFTER the balance-sheet date (e.g., a plant fire in February) which require only disclosure; (2) SEARCH FOR UNRECORDED LIABILITIES (examine cash disbursements after year-end, review unpaid invoices, inspect contracts); (3) MANAGEMENT REPRESENTATION LETTER, signed by the CEO and CFO on the date of the auditor's report, that confirms management's responsibilities and the completeness of information provided; (4) LEGAL LETTER (AU-C 501) from the client's attorneys about pending litigation, claims, and assessments; (5) FINAL ANALYTICAL PROCEDURES to help the engagement partner form an overall conclusion; and (6) REVIEW of AGGREGATED UNCORRECTED MISSTATEMENTS against materiality on a SCHEDULE OF UNADJUSTED DIFFERENCES.
GOING CONCERN is a SEPARATE and required auditor evaluation under AU-C 570 / AS 2415. Management is required to evaluate whether there is SUBSTANTIAL DOUBT about the entity's ability to continue as a going concern for a reasonable period of time (one year from the date the financial statements are issued, per ASU 2014-15 for GAAP). The auditor performs its own evaluation, considering conditions and events such as recurring losses, working capital deficiency, loan defaults, denial of usual trade credit, restructuring of debt, and loss of key customers. If substantial doubt exists, the auditor evaluates management's plans to mitigate; if the plans are likely to be effective, the auditor may issue an unmodified opinion with an EMPHASIS-OF-MATTER paragraph (private) or an EXPLANATORY paragraph (public) alerting users. If disclosure is inadequate, a QUALIFIED or ADVERSE opinion may be required.
Before signing, the engagement partner performs a FINAL ENGAGEMENT-QUALITY REVIEW (concurring partner review for public-company audits under PCAOB AS 1220), then the audit report is dated NO EARLIER than the date the auditor has obtained sufficient appropriate audit evidence (typically the date of the management representation letter). The client releases the report and the financial statements to users. Between the report date and the release date, the auditor is responsible for events that come to their attention (dual-dating may be used to limit responsibility for a specific later event to that date). After release, the auditor has no obligation to make continuing inquiries, but must respond appropriately if facts come to attention that would have caused a different report — this may require reissuing the statements or notifying regulators.
The AUDITOR'S REPORT is the deliverable users see. Under AU-C 700 (private companies) and PCAOB AS 3101 (public companies), the standard report includes: an OPINION section (positioned FIRST since 2019 for private, 2017 for public), a BASIS FOR OPINION section, KEY AUDIT MATTERS (KAM) for private-company audits electing to include them or CRITICAL AUDIT MATTERS (CAM) mandatory for public-company audits (matters that involved especially challenging, subjective, or complex auditor judgment), RESPONSIBILITIES OF MANAGEMENT for the financial statements including going-concern assessment, AUDITOR'S RESPONSIBILITIES for the audit including a description of reasonable assurance and professional skepticism, and the AUDITOR'S SIGNATURE, city and state (or country), and DATE. The report is addressed to those who engaged the auditor — usually the board or shareholders.
There are FOUR OPINION TYPES. An UNMODIFIED (or UNQUALIFIED) opinion states that the financial statements are presented fairly, in all material respects, in accordance with the applicable framework. A QUALIFIED opinion is issued when either (a) the auditor concludes that misstatements, individually or in aggregate, are MATERIAL but NOT PERVASIVE to the financial statements, or (b) a scope limitation prevents the auditor from obtaining sufficient appropriate evidence, but the possible effects are material but not pervasive. An ADVERSE opinion is issued when misstatements are BOTH MATERIAL AND PERVASIVE (the statements as a whole are misleading). A DISCLAIMER of opinion is issued when a scope limitation is so significant that the auditor cannot form an opinion, and the possible effects would be material and pervasive. Only unmodified reports include the standard clean opinion; the other three include additional paragraphs describing the basis for the modification.
Additional report content includes EMPHASIS-OF-MATTER PARAGRAPHS (drawing attention to a matter appropriately presented or disclosed — going concern, subsequent event, change in accounting principle, restatement of prior periods) and OTHER-MATTER PARAGRAPHS (matters other than those presented or disclosed — comparative statements of a predecessor auditor, restrictions on distribution). Under PCAOB standards, CRITICAL AUDIT MATTERS must be described with sufficient specificity to be useful (the account, the reason it was a CAM, and how it was addressed); they do NOT change the opinion. If the entity's SUPPLEMENTARY INFORMATION or OTHER INFORMATION (e.g., MD&A) is materially inconsistent with the audited statements, the auditor must resolve the inconsistency — usually by asking the client to correct the other information, or by describing it in the report. The signing partner's NAME is required on all PCAOB reports (Form AP filing) so users know who is accountable.
Perform the six phases of a real audit engagement on a small private-company client. You will document client acceptance, planning and risk assessment (with materiality), understanding of internal control and a walkthrough, design and perform substantive procedures over one significant account (accounts receivable), evaluate the results, and draft the auditor's report. Deliver as a single audit-workpaper binder (PDF).
Northwind Wholesale Distributors, Inc. is a private-company food-service distributor with $42 million in revenue, $8 million in accounts receivable, and 55 employees. It has never been audited. A new bank lender has requested audited financial statements as a covenant condition. Northwind's CFO, Maria Chen, has engaged your firm. Preliminary information: the entity is family-controlled (the Nguyen family owns 100%); management has aggressive growth targets; there is one AR clerk who invoices, posts cash, and prepares bank reconciliations; internal controls have never been formally documented; the previous outside CPA prepared compilations only. You are the engagement senior.
| Criterion | Weight |
|---|---|
| Client acceptance memo and engagement letter | 10% |
| Planning: strategy, risk assessment, materiality | 20% |
| Internal control documentation, walkthrough, and deficiency communication | 20% |
| Substantive procedures over AR (confirmations, cutoff, allowance) | 25% |
| Completion procedures and rep letter | 10% |
| Auditor's report draft and completion memo | 15% |