,
Chapter 1: The Role of Public Accountant
Core Concepts: Services & Risk
Types of Services (Service Pyramid)
Assurance Services (Broadest): Services aimed at improving the quality of information for decision makers.
- Attestation Services: Specifically focused on increasing the reliability of information.
- Other Assurance Services: Involves putting information into a better context or form to assist decision-making.
Non-Assurance Services: All other services CPAs provide, including but not limited to:
- Tax Services
- Management Consulting Services
- Other Services: E.g. bookkeeping.
Key Risk Definitions
Information Risk: The risk that information is materially misstated, and audits reduce this risk.
- Causes of Misstatement:
- Accidental errors
- Lack of knowledge
- Unintentional bias
- Fraud
Business Risk: The risk that a company will fail due to adverse economic conditions or poor decisions. Note that audits do NOT directly address this risk.
The Attest Function & Audits
The Attestation Process
- Management makes an Assertion about a Subject Matter.
- Evaluation against Suitable Criteria: This may include standards such as COSO (Committee of Sponsoring Organizations) or GAAP (Generally Accepted Accounting Principles).
- Evidence Gathering & Report Issue: The CPA compiles evidence and issues a report on findings.
Suitable Criteria Examples (The “Rulebooks”)
- Internal Control Audits: Criteria based on the COSO framework.
- Financial Statement Audit: Criteria based on applicable financial reporting frameworks (typically GAAP in the U.S.).
The Financial Statement Audit
- Goal: To provide a high (reasonable) level of assurance that financial statements comply with GAAP.
- Process: Gather sufficient evidence to issue an opinion.
- Audit Evidence Examples (What auditors check):
- Existence/Occurrence: Are assets/sales real?
- Completeness: Are all assets/expenses accounted for?
- Valuation: Are assets and liabilities valued correctly?
- Rights/Obligations: Does the company rightfully own the assets/owe liabilities?
- Presentation & Disclosure: Are notes complete and informative?
History & Other Audit Types
The Credibility Crisis Timeline (2000-2010)
- 2000: Panel on Audit Effectiveness established.
- 2001: Enron bankruptcy occurs, leading to significant public outcry.
- 2002: WorldCom Fraud unveils severe issues in accounting practices.
- 2002: Sarbanes-Oxley Act (SOX) enacted to enhance regulatory oversight.
- 2003: PCAOB (Public Company Accounting Oversight Board) began operations.
- 2010: Dodd-Frank Act introduced reforms in the financial industry.
Other Types of Audits (C.O.I. Framework)
- Compliance Audits: Ensuring adherence to rules (e.g., IRS audit of a tax return).
- Operational Audits: Focusing on efficiency and effectiveness (e.g., auditing a receiving department's processes).
- Integrated Audit: Combining a financial statement audit with an audit of internal controls over financial reporting; required for public companies.
Types of Auditors
- Internal Auditors: Employees of the company reporting to the Audit Committee and management; focus on operational and compliance audits.
- GAO (Government Accountability Office) Auditors: Work for Congress, auditing government agencies and contractors.
- Tax Auditors: Enforce tax laws (e.g., IRS agents).
Key Players & Regulators
The AICPA (American Institute of Certified Public Accountants)
Roles:
- National professional organization for CPAs.
- Traditional roles now partially covered by the SEC/PCAOB for public companies. Primarily sets standards for nonpublic companies.
Key Functions:
- Establish Standards:
- ASB (Auditing Standards Board): Issues Statements on Auditing Standards (SAS) for nonissuers.
- ARSC (Accounting and Review Services Committee): Issues Statements on Standards for Accounting and Review Services (SSARS).
- Research & Publication: Publishes the Journal of Accountancy.
- Continuing Professional Education (CPE): Required for maintaining CPA license.
- Self-Regulation: Manages peer reviews for firms.
- CPA Exam: Prepares and grades the Uniform CPA Examination.
The PCAOB (Public Company Accounting Oversight Board)
Created by SOX (2002).
Oversight by SEC: Protects investors through oversight.
Roles:
- Oversees audits of public companies and SEC-registered entities.
Key Duties (R.I.I.D. Mnemonic):
- Register public accounting firms.
- Issue/Establish standards (auditing, quality control, ethics).
- Inspect registered firms.
- Discipline firms and individuals.
The SEC (Securities and Exchange Commission)
- Role: U.S. government agency overseeing PCAOB.
- Objective: Protect investors by mandating full disclosure.
- Key Tools:
- Registration Statements: Required for new securities containing audited financials.
- Periodic Reporting: Includes Forms 10K (annual) and 10Q (quarterly).
- Regulation S-X: Basic accounting regulation by the SEC.
Other Standard Setters
- FASB: Sets GAAP for non-governmental entities (public & private).
- GASB: Sets accounting standards for state and local governments.
- FASAB: Sets standards for U.S. federal government accounting.
- IFAC: Sets international accounting standards through its board, IASB.
Professional Structure & the CPA Exam
The CPA Exam (Starting 2024)
Core Sections (Mandatory for all):
- AUD (Auditing)
- FAR (Financial Accounting and Reporting)
- REG (Regulation)
Discipline Sections:
- BAR
- ISC
- TCP
Organization of Firms
Legal Structure: Possible structures include:
- Sole Proprietorship
- Partnership
- Professional Corporation
- Limited Liability Partnership (LLP)
Firm Sizes/Categories:
- Local
- Regional
- National
- Big 4 (the four largest accounting firms)
Team Structure on an Audit:
- Partner: Overall responsibility, final sign-off of audit report.
- Manager: Supervises the entire audit engagement.
- Senior/Supervisor: In-charge role on a daily basis.
- Staff: Conducts detailed work under supervision.
Chapter 2: Professional Standards
Professionalism & The Auditors
What is a “Professional”?
- Common View: A “pro” signifies a person with high levels of skill or expertise, akin to athletes.
- Profession’s View (CPI): A profession entails a responsibility and dedication to the public interest.
Key Traits of a CPI Profession (The “License to Operate”)
- Recognition of a Profession Requires:
- Specialized body of knowledge.
- Formal education process.
- Standards for admission (e.g., CPA Exam).
- Code of ethics to guide conduct.
- License granted by the state.
- Obligation to society (serving public interest).
The CPA License: Rights and Responsibilities
- Granted by: State Boards of Accountancy.
- Requirements: Education, CPA Exam, and relevant experience.
- Rights Granted: Unique right to sign an audit.
- Responsibilities Accepted:
- Adhere to professional standards (e.g., GAAS).
- Follow a code of professional conduct.
- Pursue Continuing Professional Education (CPE) courses.
The Three Sets of Auditing Standards
The Standards Are Set By…
- Public Companies (Issuers) in the U.S.: Set by PCAOB (Public Company Accounting Oversight Board).
- Nonpublic Companies (Nonissuers) in the U.S.: Established by AICPA (through Auditing Standards Board, ASB).
- These are referred to as GAAS (Generally Accepted Auditing Standards).
- Companies Anywhere (Internationally): Set by IAASB (International Auditing and Assurance Standards Board).
- These standards are called International Standards on Auditing (ISA).
Who Sets the Rules for Auditing a Private Tech Startup in Texas?
- AICPA.
Who Sets the Rules for Auditing Apple?
- PCAOB.
Principles Underlying a GAAS Audit (The “P.A.P.R.” Framework)
Key Components:
- Purpose: To provide an opinion regarding whether financial statements align with applicable financial reporting frameworks (e.g., GAAP).
- Premise: Management is responsible for:
- Preparing financial statements.
- Sharing all information and providing unrestricted access to auditors.
- Responsibilities of the Auditor:
- Competence and Capabilities: Auditors must demonstrate appropriate skills and capabilities.
- Professional Skepticism: A mindset involving questioning and critical analysis of evidence.
- Professional Judgment: Application of knowledge and experience to inform decisions during audits.
Actions & Reporting
- Actions:
- Obtain reasonable assurance (not absolute assurance) that statements are materially free from misstatement (error or fraud).
- Reporting:
- Auditors must express a written opinion or state that an opinion cannot be expressed.
Auditor Responsibility for… (The “Levels of Responsibility”)
| Item | Auditor’s Responsibility |
|---|---|
| Errors & Fraud | Plan and perform the audit to achieve reasonable assurance of detecting material misstatements; apply professional skepticism. |
| Laws with Direct Effect | Same as for errors/fraud: achieve reasonable assurance of detecting noncompliance. |
| Laws with Indirect Effect | No assurance provided; inquiry and investigation required upon finding evidence of potential noncompliance. |
The Auditor’s Report (A Side-by-Side Comparison)
Key Differences Between Public and Nonpublic Company Reports
| Report Element | Public Company (PCAOB) | Nonpublic Company (AICPA/GAAS) |
|---|---|---|
| Title | Includes "Registered" and "Independent" | Includes "Independent" |
| Addressee | Shareholders and Board of Directors | Company, Shareholders, Audit Committee, etc. |
| Standards Referenced | Standards of the PCAOB | Auditing standards GAAS |
| Key Sections | Opinion, Basis for Opinion, Critical Audit Matters (CAMs) | Opinion, Basis for Opinion, Management’s Responsibilities, Auditor’s Responsibilities |
| Internal Control | Required to cite audit of Internal Controls over Financial Reporting (ICFR) | No explicit opinion on ICFR expressed; understood only for audit planning. |
| Auditor Tenure | Must state the year the firm began serving the client | Not required. |
| Signature | Name of CPA firm | Name of CPA firm (or individual if sole practitioner) |
| Date | No earlier than when sufficient evidence is obtained | No earlier than when sufficient evidence is obtained |
New/Important Concepts in Reports
Critical Audit Matters (CAMs):
- Required for public companies, referring to matters that present especially challenging, subjective, or complex auditor judgment. Communicating CAMs does not change the opinion on financial statements.
Key Audit Matters (KAMs):
- Similar to CAMs but required for international audits of listed companies under different standards.
Other Types of Audit Opinions (Beyond the “Clean” Opinion”)
- Unmodified (Unqualified): Financial statements follow GAAP.
- Qualified: Some issues exist, but they are not pervasive (for example, a scope limitation or departure from GAAP).
- Adverse: Significant GAAP departure renders statements misleading.
- Disclaimer: Auditor cannot provide an opinion due to massive scope limitations.
Quality Management (Control) for CPA Firms
- CPA firms need systems in place to ensure compliance with professional standards.
The 8 Components of AICPA Quality Management Standards (The R.G.R.A.R.I.M.M. Mnemonic)
- Risk Assessment Process: Identifying and responding to risks of quality.
- Governance and Leadership: Commitment to quality from the top management ("Tone at the top").
- Relevant Ethical Requirements: Including independence confirmations.
- Acceptance and Continuance: Client integrity and competence assessments in taking/keeping clients.
- Engagement Performance: Involves supervision, consultation, documentation of engagements.
- Resources: Human, technological and intellectual resources.
- Information and Communication: Sharing quality-related information within the firm.
- Monitoring and Remediation: Inspecting engagements and resolving identified quality issues.
PCAOB Quality Control Elements
- Similar to AICPA, with specific focus areas.
- Elements include Personnel Management, Independence/Integrity, Acceptance/Continuance, Engagement Performance, and Monitoring.
Reviews and Inspections (The “Layers of Review”)
- Engagement Quality Review:
- A “cold review” conducted by a partner not involved with the team before report issuance; required for public companies audits.
- Inspections of Completed Engagements:
- Internal inspections to assess compliance with quality control policies.
- Peer Reviews:
- Required for AICPA members. Two types:
- System Review: In-depth assessment of the firm's quality control system for audit practices.
- Engagement Review: Examines a sample of reports for firms with minimal audit engagements.
- Required for AICPA members. Two types:
- PCAOB Inspections:
- Conducted by PCAOB staff to review registered firms’ audits of public companies, resulting in reports issued to SEC.
Other Key Audits (Special Cases)
Governmental Audits (Yellow Book)
- Issued by the GAO, with additional requirements beyond GAAS for entities receiving federal funds.
Single Audit Act
- Applicable to state/local governments or non-profits spending over $750,000 in federal awards; necessitates auditing financial statements and compliance with federal programs.
Employee Benefit Plan Audits (ERISA)
- Required by the DOL for retirement plans with specific requirements, including a review of the plan document; “limited scope” audits allowed under certain conditions.
Chapter 3: Professional Ethics
The Foundation: Ethics & The Code
Why Ethics?
- CPAs hold a unique responsibility to serve the public interest, given the credibility of their work.
- Public confidence in the profession hinges on the ethical integrity maintained by CPAs.
- The Code of Professional Conduct outlines these responsibilities, providing guidelines and rules that are essential for fulfilling them.
The Structure of the AICPA Code (The “Pyramid”)
- Principles: Broad, philosophical goals (the “why”).
- Rules: Minimum standards of enforceable conduct (the “what”).
- Interpretations: Guidelines for applying rules in specific situations.
The Three Parts of the Code
Organized according to the member’s professional role:
- Part 1: Members in Public Practice (auditors, tax preparers).
- Part 2: Members in Business (CFOs, controllers, accountants in a company).
- Part 3: Other Members (retired or not currently working).
The Conceptual Framework: A 3-Step Process
The essential application when explicit rules do not cover a situation:
- Identify Threats: Determine if the relationship poses a threat to compliance.
- Evaluate Safeguards: Assess whether safeguards can mitigate the threat to an acceptable level.
- Apply Safeguards or Exit: If safeguards reduce the risk, continue; if not, refuse or withdraw from service.
Core Idea
- The scenario should allow a