Chapter 1 Auditing and Assurance Services

Chapter 1 — Auditing & Assurance Services

The whole chapter in one simple idea

A company creates financial statements → management claims the numbers are correct → an independent auditor checks evidence → the auditor reports whether the statements can be trusted.

Audits reduce information risk, but they cannot guarantee that the company will succeed.


Slides 1–7: Why do we need auditors?

Slide 1 — Chapter Introduction

Auditing helps investors trust financial information.

  • Investors put money into companies they usually do not control.

  • They need someone independent to check management’s financial statements.

  • That independent checker is the auditor.

Big idea: People are more willing to invest when they trust the numbers.


Slide 2 — Learning Objectives, Part 1

You will learn:

  1. Why unreliable information is risky.

  2. The difference between auditing, attestation, and assurance.

  3. The claims—or assertions—management makes in financial statements.

These three topics build on each other:

Management makes claims → auditor checks claims → users receive more reliable information.


Slide 3 — Learning Objectives, Part 2

You will also learn:

  1. Professional skepticism.

  2. How public accounting firms work.

  3. Different auditors and audits.

  4. How someone becomes a CPA or earns another certification.


Slide 4 — Demand for Reliable Information

Investors face two different risks:

Information risk

The financial information could be materially wrong or misleading.

  • Unintentional: accounting mistake, lack of knowledge, data-entry error.

  • Intentional: management purposely commits fraud.

“Materially wrong” means wrong enough to affect someone’s decision.

Business risk

The company might fail to achieve its goals.

Examples:

  • Poor sales

  • Too much debt

  • Unable to pay bills

  • Bad management decisions

Important difference: An audit reduces information risk, not business risk.

An auditor can say, “The financial statements are fairly presented,” but cannot promise, “This company will never fail.”


Slide 5 — Bed Bath & Beyond Stock: 1992–2023

The graph shows the company’s stock rising to around $77 and eventually dropping close to zero.

Lesson: A company can perform well for many years and still experience serious business problems later.

An audit does not protect investors from every bad investment—it helps them receive more reliable information when making the decision.


Slide 6 — Bed Bath & Beyond Stock: 2022–2023

The stock briefly jumped before continuing to fall.

Why might the professor show this?

A temporary increase in stock price does not necessarily mean the company’s underlying business is healthy. Investors need reliable information, not just excitement or market hype.


Slide 7 — Audit Quality

This slide only gives the topic, so it is probably meant for class discussion.

Audit quality means the auditor:

  • Has the proper skills and experience.

  • Remains independent.

  • Collects enough reliable evidence.

  • Finds important errors or fraud.

  • Reports the findings appropriately.

Simple version: A high-quality audit is a careful, unbiased check—not merely signing an audit report.


Slides 8–16: Audit vs. Attestation vs. Assurance

Slide 8 — Definition of Financial Statement Auditing

The textbook definition is long, but the process is simple:

  1. Management makes assertions about the financial statements.

  2. The auditor objectively gathers evidence.

  3. The auditor compares the claims against GAAP.

  4. The auditor communicates the conclusion in an audit report.

  5. Investors, creditors, and other users rely on that report.

Important terms
  • Systematic: follows an organized audit process.

  • Objective: unbiased and independent.

  • Evidence: documents, confirmations, observations, calculations, etc.

  • Established criteria: the rules used to judge the information, usually GAAP.

  • Interested users: investors, lenders, creditors, and others.


Slide 9 — Overview of Financial Statement Auditing

This picture shows the full audit process:

Management’s financial statements and assertions
↓
Independent auditor collects evidence
↓
Auditor compares information with GAAP or IFRS
↓
Auditor issues the audit report

Evidence can include:

  • Examining documents

  • Observing physical assets

  • Asking management questions

  • Confirming information with outside parties

  • Learning how the client’s business operates

Important: Asking management is not enough. The auditor must verify the answer with evidence.


Slide 10 — Attestation Engagements

An attestation engagement happens when management makes a claim about a specific subject, and a practitioner examines whether that claim can be trusted.

Examples include:

  • Financial forecasts

  • Pro forma financial information

  • Management Discussion and Analysis

  • Internal control effectiveness

  • Environmental compliance

  • Sustainability reports

Simple example: Management says, “Our internal controls are effective.” The CPA checks that claim and reports a conclusion.

A financial statement audit is one type of attestation engagement.


Slide 11 — Assurance Services

Assurance services are independent services that improve the quality or usefulness of information.

Examples:

  • Financial statement audits

  • Cyber-risk assurance

  • Fraud-risk assessments

  • Customer-satisfaction information

  • ESG reports

  • XBRL reporting

  • Internal audit outsourcing

Simple version: Assurance makes information easier to trust or use when making decisions.


Slide 12 — Sustainability Reporting

Companies increasingly think about the “three Ps”:

  • Planet: environmental impact

  • People: employees and society

  • Profit: financial performance

Sustainability reporting primarily focuses on planet and people.

Examples:

  • Pollution or carbon emissions

  • Employee safety

  • Community impact

  • Diversity information

Investors may want a CPA to check whether this information is reliable.


Slide 13 — ESG as an Opportunity for CPAs

ESG stands for:

  • Environmental

  • Social

  • Governance

Companies report ESG information, but users need standards to judge it.

Standards provide:

  • The measures companies should report.

  • Criteria auditors can use.

  • A way to compare companies.

  • A basis for providing assurance.

Big idea: CPAs can provide assurance over more than financial statements.


Slide 14 — Growth in ESG Reporting and Assurance

Among S&P 500 companies:

  • In 2010, 38% issued ESG reports, and 16% of those received assurance.

  • In 2020, 76% issued ESG reports, and 46% of those received assurance.

Meaning: More companies are reporting ESG information, and more companies are paying independent professionals to verify it.


Slide 15 — Who Provides ESG Assurance?

Financial auditors are not the only professionals providing ESG assurance.

Other providers include:

  • ERM

  • Lloyd’s

  • Bureau Veritas

  • Apex

  • Other specialized firms

In 2020, financial auditors provided about 19% of ESG assurance engagements.

Main lesson: ESG assurance is a growing market, but CPA firms compete with many non-accounting specialists.


Slide 16 — Relationship Between the Three Services

Think of three circles:

  • Assurance is the largest category.

  • Attestation is inside assurance.

  • Auditing is inside attestation.

Therefore:

Every audit is attestation and assurance, but not every assurance service is an audit.

Example:

  • Financial statement audit → all three.

  • Checking management’s sustainability claim → attestation and assurance.

  • Improving customer-satisfaction information → assurance, but possibly not attestation.


Slides 17–22: Management Assertions and Skepticism

Slide 17 — Sarbanes-Oxley Act of 2002

Congress passed the Sarbanes-Oxley Act, commonly called SOX, after major accounting scandals such as Enron and WorldCom.

SOX increased corporate accountability.

Most important idea: Management—not the auditor—is responsible for:

  • The financial reporting process

  • The financial statements

  • The company’s internal controls

The auditor checks management’s work but does not create management’s responsibility.


Slide 18 — CEO and CFO Certification

Under SOX Section 302, the CEO and CFO certify that:

  • They read the financial statements.

  • They are not aware of major false statements or missing disclosures.

  • They believe the statements fairly show the company’s financial condition.

For certain larger public companies called accelerated filers:

  • Management reports on internal controls.

  • Under Section 404, the auditor also reports on internal control over financial reporting.

Simple version: The CEO and CFO cannot blame the auditor by saying, “We didn’t know the financial statements were wrong.”


Slide 19 — Management’s Five Assertions

Assertions are the promises management automatically makes when it presents financial statements.

Assertion

Simple question

Existence or occurrence

Is it real?

Completeness

Did we include everything?

Valuation or allocation

Is it recorded for the correct amount?

Rights and obligations

Does the company own it or owe it?

Presentation and disclosure

Is it classified and explained properly?

Example: Inventory

Management is claiming:

  • The inventory really exists.

  • All inventory is included.

  • Inventory has the correct value.

  • The company owns the inventory.

  • Inventory is properly presented and disclosed.

These assertions become the auditor’s testing targets.


Slide 20 — Assertions for Transactions and Balances

Different assertions apply depending on what the auditor is testing.

Transactions
  • Occurrence: Did the recorded transaction actually happen?

  • Completeness: Were all transactions recorded?

  • Accuracy: Was the correct amount recorded?

  • Cutoff: Was it recorded in the correct period?

  • Classification: Was it recorded in the correct account?

Account balances
  • Existence: Does the asset or liability exist?

  • Completeness: Are all balances included?

  • Valuation: Is the balance correct?

  • Rights and obligations: Does the company own the asset or owe the liability?

Helpful exam trick
  • Worried something recorded is fake or overstated? Test existence/occurrence.

  • Worried something was left out or understated? Test completeness.

  • Worried December sales were recorded in January? Test cutoff.


Slide 21 — Professional Skepticism

Professional skepticism means having a questioning mind and critically evaluating evidence.

The auditor should:

  • Ask questions.

  • Obtain answers.

  • Verify those answers.

  • Investigate unusual trends.

  • Check whether documents are authentic.

  • Look for evidence that supports or contradicts management.

Important: Inquiry alone is never enough.

Management wants the company to appear successful. The auditor must independently determine whether that picture is fair.


Slide 22 — Auditors Must Be Skeptical

Professional skepticism does not mean assuming management is lying.

It means the auditor should:

  • Remain neutral.

  • Consider both supporting and contradictory evidence.

  • Watch for possible errors and fraud.

  • Evaluate whether evidence is relevant and reliable.

  • Refuse to accept weak or unpersuasive evidence.

  • Consider management’s bias and the auditor’s own bias.

Best way to remember it: Trust is not audit evidence—verify it.


Slides 23–29: CPA Firms and Different Auditors

Slide 23 — Services Offered by Public Accounting Firms

CPA firms generally offer three major service groups:

Assurance
  • Financial statement audits

  • Attestation engagements

  • Reviews

  • Compilations

  • Other assurance services

Tax
  • Preparing tax returns

  • Tax planning

  • Tax compliance

Consulting and advisory
  • Technology consulting

  • Risk consulting

  • Business strategy

  • System design and implementation

Quick assurance comparison
  • Audit: reasonable assurance; most testing.

  • Review: limited assurance; mainly questions and analytical procedures.

  • Compilation: organizes management’s information; no assurance.


Slides 24–25 — Prohibited Services

SOX prevents an audit firm from performing certain services for its public-company audit clients.

Examples include:

  • Bookkeeping

  • Designing financial information systems

  • Valuation services

  • Internal audit outsourcing

  • Management or HR services

  • Certain legal and investment services

Why are these prohibited?

  1. The auditor should not make management decisions.

  2. The auditor should not audit their own work.

Example: If the auditor creates the company’s accounting system and then audits that system, independence is weakened.

Some tax and other permitted services may be provided when the audit committee approves them in advance. The firm can also provide prohibited services to companies it does not audit.


Slide 26 — Big Four Revenue in 2021

The Big Four are:

  • Deloitte

  • EY

  • KPMG

  • PwC

The table shows that they earn money from audit, tax, and advisory services.

Deloitte earned 61% of its 2021 revenue from advisory services.

Main lesson: The Big Four are not only audit firms. They are large professional-service organizations.


Slide 27 — Big Four Revenue in 2024

Firm

Total revenue

Audit/assurance

Tax

Advisory/other

Deloitte

$67.2B

31%

17%

52%

EY

$51.2B

34%

24%

42%

KPMG

$38.4B

35%

23%

42%

PwC

$55.4B

35%

23%

42%

What to notice: Audit is extremely important, but advisory and tax make up a large portion of Big Four revenue.


Slide 28 — Public Accounting Firm Organization

A typical career ladder is:

  1. Staff/associate: performs detailed testing and prepares documentation.

  2. Senior: leads daily fieldwork and reviews staff work.

  3. Manager: manages engagements and communicates with the client.

  4. Partner: accepts responsibility for the engagement and signs the report.

  5. Managing partner/executive committee: leads the overall firm or office.

The firm is also separated into service lines:

  • Assurance

  • Tax

  • Advisory


Slide 29 — Types of Auditors

Auditor

Main job

External auditor/CPA

Determine whether financial statements are reliable

Internal auditor/CIA

Improve operations, controls, efficiency, and compliance

Government auditor

Check compliance within governmental organizations

Regulatory auditor

Enforce industry-specific government rules

Examples of regulatory auditors include:

  • IRS auditors

  • Bank regulators

  • Insurance regulators

Difference: External auditors are independent from the client. Internal auditors usually work for or serve the organization itself.


Slides 30–36: CPA Exam and Certifications

Slide 30 — Becoming a Professional

Becoming a CPA generally involves:

  1. Education

  2. Passing the CPA Exam

  3. Required work experience

  4. State certification and licensing

  5. Continuing to develop professional skills

Exact requirements depend on the state.


Slide 31 — CPA Exam Structure

Starting with the exam structure shown in the slides, candidates take three required core sections:

  • AUD: Auditing and Attestation

  • FAR: Financial Accounting and Reporting

  • REG: Taxation and Regulation

They also choose one discipline:

  • BAR: Business Analysis and Reporting

  • ISC: Information Systems and Controls

  • TCP: Tax Compliance and Planning

That means: three core sections + one discipline = four sections total.


Slide 32 — CPA Exam Details

According to the slide:

  • Each section is four hours.

  • Candidates must pass all four sections.

  • A passing score is 75.

  • Questions include multiple-choice questions and task-based simulations.

For AUD, the slide lists:

  • 78 multiple-choice questions

  • 7 task-based simulations

  • Each question type makes up 50% of the score

These exam details can change, so use the slide’s information for your class unless your professor says otherwise.


Slide 33 — AUD Exam Blueprint

The largest AUD content area is:

  • Performing procedures and obtaining audit evidence: 30–40%

Other areas include:

  • Assessing risk and planning: 25–35%

  • Ethics and professional responsibilities: 15–25%

  • Forming conclusions and reporting: 10–20%

Meaning: AUD is not only memorization. You must apply audit rules, evaluate evidence, identify risk, and reach conclusions.


Slides 34–36 — Other Professional Certifications

Certification

Main focus

CPA

Public accounting, external auditing, financial reporting, and tax

CISA

Auditing information systems and cybersecurity controls

CIA

Internal auditing, operations, risk, and company controls

CFE

Fraud prevention, detection, and investigation

CMA

Management accounting, financial planning, and business decisions

The slides compare their education, experience, exams, passing scores, and administering organizations.

What you should mainly remember: Know what type of career each certification supports. You probably do not need to memorize every test length or passing score unless your professor specifically says so.


Slides 37–40: Who Regulates Auditing?

Slide 37 — AICPA’s Traditional Role

Before 2003, the AICPA established auditing standards for public and private companies.

After SOX:

  • The PCAOB received standard-setting authority over audits of public companies.

  • The AICPA continued its role for nonpublic-company audits.

  • The AICPA continued administering the CPA Exam.


Slide 38 — PCAOB

The Public Company Accounting Oversight Board was created by SOX.

It oversees auditors of public companies by:

  • Registering public accounting firms

  • Creating auditing and independence standards

  • Inspecting accounting firms

  • Investigating violations

  • Disciplining and sanctioning firms

Simple version: The PCAOB watches the auditors who audit public companies.


Slides 39–40 — SEC

The Securities and Exchange Commission is a federal government agency that protects investors.

The SEC:

  • Oversees the PCAOB.

  • Requires public companies to disclose financial information.

  • Works to prevent securities fraud.

  • Requires registration statements when securities are offered to the public.

  • Requires audited financial statements in certain filings.

  • Issues financial-reporting rules, including Regulation S-X.

Easy regulatory chain

SEC oversees the securities market and PCAOB
↓
PCAOB oversees auditors of public companies
↓
CPA firms audit public companies
↓
Management prepares the financial statements


Slide 41 — End of Chapter

No new material—just the end of the presentation.

Most important things to know

  1. Audit reduces information risk, not business risk.

  2. Assurance → Attestation → Audit from broadest to narrowest.

  3. Management prepares the statements; the auditor independently checks them.

  4. Know the five assertions:

    • Existence/occurrence

    • Completeness

    • Valuation/allocation

    • Rights and obligations

    • Presentation and disclosure

  5. Professional skepticism means ask, obtain evidence, and verify.

  6. Auditors cannot make management decisions or audit their own work.

  7. Know the difference between external, internal, governmental, and regulatory auditors.

  8. SEC oversees the PCAOB; PCAOB oversees public-company auditors.

From your course schedule, Chapter 1 is covered on August 25 and 27, appears on Quiz 1 with Chapters 1–3, and is included in Exam 1 with Chapters 1–4.