Free CPA AUD (Auditing & Attestation) Assessing Risk and Developing a Planned Response Practice Questions

Master risk assessment and planned response for the CPA AUD exam. Questions cover understanding the entity, identifying risks of material misstatement, planning the audit, and designing appropriate procedures.

303 Questions
110 Easy
113 Medium
80 Hard
2026 Syllabus

Sample Questions

Question 1 Easy
Which of the following is an example of an IT general control?
Solution
B is correct. IT general controls (ITGCs) are policies and procedures that relate to many applications and support the effective functioning of application controls. Access management — including role-based authentication and periodic access reviews — is a fundamental ITGC category.
A is incorrect. A three-way match is an application control (or a manual control within a business process) that operates within the purchasing/disbursements cycle. It is not an IT general control.
C is incorrect. Manual review of aging reports is a manual detective control within the revenue cycle. It does not relate to the IT environment broadly and is not an ITGC.
D is incorrect. Requiring dual signatures on checks is a manual authorization control within the disbursement process. This is a business process control, not an IT general control.
Question 2 Medium
Under COSO's Internal Control — Integrated Framework, which of the following best illustrates the risk assessment component?
Solution
A is correct. Under COSO, the risk assessment component involves management's process for identifying and analyzing risks relevant to achieving the entity's objectives, including financial reporting objectives. This includes evaluating the likelihood and significance of risks and determining how they should be managed. Board review of financial results against budget (B) is a monitoring activity. Establishing a code of conduct (C) is part of the control environment component. An automated validation control in the payroll application (D) is a control activity (specifically, an application control).
Question 3 Hard
An auditor is planning the audit of a multinational entity with subsidiaries in 15 countries. The group engagement partner must determine the scope of work to be performed at each component. Several subsidiaries are audited by component auditors from different firms. Under AU-C 600, the group engagement partner should:
Solution
A is correct. Under AU-C 600, the group engagement partner is responsible for the direction, supervision, and performance of the group audit engagement. This includes determining the type of work to be performed at each component (full audit, specified procedures, or analytical procedures) based on the component's significance, evaluating the competence and objectivity of component auditors, establishing communications, and reviewing component auditors' work. Performing all work centrally (B) is impractical and not required. Accepting work solely based on network membership (C) does not satisfy the group engagement partner's responsibility to evaluate competence and objectivity. Limiting to parent company records (D) would fail to obtain sufficient evidence about the group financial statements.
Create a Free Account to Access All 303 Questions →

More CPA AUD Topics

About FreeFellow

FreeFellow is a free exam prep platform for actuarial (SOA & CAS), CFA, CFP, CPA, CAIA, and securities licensing candidates. Every question includes a detailed solution. Full lessons, flashcards with spaced repetition, timed mock exams, performance analytics, and a personalized study plan are all included — no paywalls, no ads.