Keentune

Auditing & Attestation curriculum

21 chapters
·
141 concepts
·
free
Everything the adaptive question bank can teach and test in Auditing & Attestation, from foundations through advanced practice. Work through it in order, or start practising and let the questions find your level.
New here? Read the Auditing & Attestation guide
A free 16-minute primer — the mental model, the mistakes beginners make, and what to practise first.
A. Engagements & responsibilities
Reasonable assurance on statements as a whole; opinion output.
Audit vs review vs compilation vs preparation — assurance ladder.
Attest engagements beyond statements (examinations, AUP).
Statements are management's; opinion is the auditor's.
Terms, scope, responsibilities in writing.
Required inquiries before acceptance.
Firm-level quality systems concept; EQR concept.
Issuer vs nonissuer standard-setting lanes.
B. Ethics & independence
Both required for audits.
Self-review, familiarity, advocacy, self-interest, intimidation — name and counter.
Direct vs material-indirect interest rules.
Prohibited services for audit clients (issuer strictness).
Contingent-fee and commission restrictions.
Client information limits and exceptions (subpoena, peer review).
The everyone-always baseline.
C. Risk assessment & planning
AR = IR × CR × DR — solve the lever (computed family).
Complexity, estimates, incentives raising IR.
Overall + performance materiality logic.
Industry, environment, internal control walk.
Required planning analytics — expectation building.
Required team discussion; professional skepticism.
Incentive, opportunity, rationalization — classify the cue.
Revenue-recognition presumption; management override.
Strategy vs detailed plan; timing choices.
Component auditors, specialists, internal-audit reliance.
D. Internal control
Environment, risk assessment, activities, info/communication, monitoring.
Assertion-linked control design.
Tracing one transaction end-to-end.
Evaluate design, then test operation.
Inquiry+observation+inspection+reperformance mix.
Control risk below max → reduce substantive work.
Deficiency → significant deficiency → material weakness.
ARC (authorization, recording, custody) separations (classification family).
General vs application controls; access and change management.
Integrated-audit concept for issuers.
E. Evidence & procedures
Existence, completeness, accuracy, cutoff, classification, rights, valuation — map the test (classification family).
Vouching (existence) vs tracing (completeness) — the direction trap.
External > internal; auditor-obtained > entity-provided.
Quantity vs quality of evidence.
Positive vs negative; nonresponse handling.
Attendance at counts; alternative procedures.
Precision of expectation drives assurance.
Auditing estimates: methods, assumptions, data.
Identification and substance scrutiny.
Legal letters and management inquiry.
Written representations — required, never a substitute.
Workpapers: experienced-auditor standard, retention, lockdown.
F. Sampling
Controls vs balances sampling lanes.
Incorrect acceptance/rejection; over/under-reliance — which hurts effectiveness (classification family).
Tolerable rate/misstatement, expected error, population (direction family).
Projecting misstatements; upper-limit logic.
Monetary-unit sampling intuition.
G. Cycles & directional tests
Cutoff, confirmations, credit memos after year-end.
Search for unrecorded liabilities — the completeness classic.
Count-to-record, price testing, obsolescence.
Existence of employees; rate/hour authorization.
Bank recs, cutoff statements, kiting/lapping patterns (computed/diagnostic family).
Confirmation and covenant checks.
Additions vouching; repairs-vs-capital scan.
H. Completion & reporting
Opinion structure; basis; KAM/CAM concepts.
Material vs pervasive → qualified/adverse/disclaimer (computed-grid family).
Client- vs circumstance-imposed; the disclaimer path.
Substantial doubt: emphasis/separate section logic.
When each paragraph type fits.
Prior-period opinions and predecessor reporting.
Type I/II handling; dual dating.
Facts discovered after the report.
Reference vs assume responsibility.
Auditor duty over annual-report other info.
Required TCWG communications.
SSARS report shapes and negative assurance.
I. Government & other frameworks
Yellow Book additions at concept level.
Federal-award compliance auditing idea.
Cash/tax/regulatory framework reporting.
SOC 1/2 attest structure from the auditor side.
J. IT audit detail
Computer-assisted techniques; auditing through the computer.
Test-data and parallel-simulation concepts.
Access/change-management control tests.
Benchmarking one instance + GITC reliance logic.
Full-population analytics vs sampling trade-off.
K. Fraud procedures detail
Required JE testing: criteria and timing.
Channel stuffing, bill-and-hold abuse, side agreements.
Skimming vs larceny vs billing schemes recognition.
Estimates bias review; unusual transactions.
Escalation and withdrawal considerations.
L. Procedures by area — extras
Reasonableness testing of payroll populations.
Occurrence testing of expenses.
Auditor range vs management point estimate.
Initial-engagement opening-balance work.
Discovering omitted procedures post-report.
Roll-forward from interim testing.
M. Completion extras
Required overall review analytics.
Accumulating and evaluating misstatements.
Two evaluation approaches concept.
Communicating uncorrected misstatements.
EQR before release.
N. Attestation & SSARS detail
Assurance levels across attest types (classification family).
Prospective statements: who may use projections.
Pro-forma attestation concept.
Attesting compliance with requirements.
Inquiry + analytics; no opinion, limited assurance.
Reporting when independence is impaired.
Compilations omitting substantially all disclosures.
No-report preparation engagements.
O. Issuer-specific & ethics extras
Rotation and cooling-off concepts.
Service preapproval duty.
Inspection regime concept.
Permissible tax services boundaries.
Client-employment cooling-off concept.
P. Reporting extras
In-relation-to reporting concept.
RSI limited procedures.
Derived-statements reporting.
Issuer interim-review reports.
Restricted-use report situations.
Direct assistance boundaries.
Q. Evidence technique extras
Sales/purchases cutoff around period end.
Interbank transfers exposing kiting (computed).
AR alternative procedure after nonresponse.
Handling refused/limited legal letters.
Evaluating a specialist's work and objectivity.
R. Planning & materiality detail
Choosing the materiality base.
Group-audit allocation concept.
Timing trade-offs.
Review scope on first-year audits.
Scoping systems and reports relied on.
S. Evidence reliability detail
Testing information produced by the entity.
User-auditor use of SOC reports.
When negatives are allowed.
Authenticity considerations.
Full-population scans as procedures.
T. Reporting scenario detail
Missed count → report path (computed-grid).
Justified departure handling.
Missing-note modifications.
Different opinions across years.
Reference wording effects.
Restated priors and reissue.
U. Ethics case detail
Covered-member family rules.
Permitted-loan exceptions.
Thresholds of acceptability.
Client records return duties.
What's permissible.
Keentune is not affiliated with or endorsed by the organizations whose documentation informs these maps.
All about Auditing & Attestation practice
Also on your phone
All exam, test, and product names and trademarks are the property of their respective owners and are used here for identification and reference only. Keentune is independent study practice — not affiliated with, authorized, or endorsed by any of these organizations.
© 2026 SportaApp LLC