Chapter 1 Auditing and Assurance Services
Chapter 1 — Auditing & Assurance Services
The whole chapter in one simple idea
A company creates financial statements → management claims the numbers are correct → an independent auditor checks evidence → the auditor reports whether the statements can be trusted.
Audits reduce information risk, but they cannot guarantee that the company will succeed.
Slides 1–7: Why do we need auditors?
Slide 1 — Chapter Introduction
Auditing helps investors trust financial information.
Investors put money into companies they usually do not control.
They need someone independent to check management’s financial statements.
That independent checker is the auditor.
Big idea: People are more willing to invest when they trust the numbers.
Slide 2 — Learning Objectives, Part 1
You will learn:
Why unreliable information is risky.
The difference between auditing, attestation, and assurance.
The claims—or assertions—management makes in financial statements.
These three topics build on each other:
Management makes claims → auditor checks claims → users receive more reliable information.
Slide 3 — Learning Objectives, Part 2
You will also learn:
Professional skepticism.
How public accounting firms work.
Different auditors and audits.
How someone becomes a CPA or earns another certification.
Slide 4 — Demand for Reliable Information
Investors face two different risks:
Information risk
The financial information could be materially wrong or misleading.
Unintentional: accounting mistake, lack of knowledge, data-entry error.
Intentional: management purposely commits fraud.
“Materially wrong” means wrong enough to affect someone’s decision.
Business risk
The company might fail to achieve its goals.
Examples:
Poor sales
Too much debt
Unable to pay bills
Bad management decisions
Important difference: An audit reduces information risk, not business risk.
An auditor can say, “The financial statements are fairly presented,” but cannot promise, “This company will never fail.”
Slide 5 — Bed Bath & Beyond Stock: 1992–2023
The graph shows the company’s stock rising to around $77 and eventually dropping close to zero.
Lesson: A company can perform well for many years and still experience serious business problems later.
An audit does not protect investors from every bad investment—it helps them receive more reliable information when making the decision.
Slide 6 — Bed Bath & Beyond Stock: 2022–2023
The stock briefly jumped before continuing to fall.
Why might the professor show this?
A temporary increase in stock price does not necessarily mean the company’s underlying business is healthy. Investors need reliable information, not just excitement or market hype.
Slide 7 — Audit Quality
This slide only gives the topic, so it is probably meant for class discussion.
Audit quality means the auditor:
Has the proper skills and experience.
Remains independent.
Collects enough reliable evidence.
Finds important errors or fraud.
Reports the findings appropriately.
Simple version: A high-quality audit is a careful, unbiased check—not merely signing an audit report.
Slides 8–16: Audit vs. Attestation vs. Assurance
Slide 8 — Definition of Financial Statement Auditing
The textbook definition is long, but the process is simple:
Management makes assertions about the financial statements.
The auditor objectively gathers evidence.
The auditor compares the claims against GAAP.
The auditor communicates the conclusion in an audit report.
Investors, creditors, and other users rely on that report.
Important terms
Systematic: follows an organized audit process.
Objective: unbiased and independent.
Evidence: documents, confirmations, observations, calculations, etc.
Established criteria: the rules used to judge the information, usually GAAP.
Interested users: investors, lenders, creditors, and others.
Slide 9 — Overview of Financial Statement Auditing
This picture shows the full audit process:
Management’s financial statements and assertions
↓
Independent auditor collects evidence
↓
Auditor compares information with GAAP or IFRS
↓
Auditor issues the audit report
Evidence can include:
Examining documents
Observing physical assets
Asking management questions
Confirming information with outside parties
Learning how the client’s business operates
Important: Asking management is not enough. The auditor must verify the answer with evidence.
Slide 10 — Attestation Engagements
An attestation engagement happens when management makes a claim about a specific subject, and a practitioner examines whether that claim can be trusted.
Examples include:
Financial forecasts
Pro forma financial information
Management Discussion and Analysis
Internal control effectiveness
Environmental compliance
Sustainability reports
Simple example: Management says, “Our internal controls are effective.” The CPA checks that claim and reports a conclusion.
A financial statement audit is one type of attestation engagement.
Slide 11 — Assurance Services
Assurance services are independent services that improve the quality or usefulness of information.
Examples:
Financial statement audits
Cyber-risk assurance
Fraud-risk assessments
Customer-satisfaction information
ESG reports
XBRL reporting
Internal audit outsourcing
Simple version: Assurance makes information easier to trust or use when making decisions.
Slide 12 — Sustainability Reporting
Companies increasingly think about the “three Ps”:
Planet: environmental impact
People: employees and society
Profit: financial performance
Sustainability reporting primarily focuses on planet and people.
Examples:
Pollution or carbon emissions
Employee safety
Community impact
Diversity information
Investors may want a CPA to check whether this information is reliable.
Slide 13 — ESG as an Opportunity for CPAs
ESG stands for:
Environmental
Social
Governance
Companies report ESG information, but users need standards to judge it.
Standards provide:
The measures companies should report.
Criteria auditors can use.
A way to compare companies.
A basis for providing assurance.
Big idea: CPAs can provide assurance over more than financial statements.
Slide 14 — Growth in ESG Reporting and Assurance
Among S&P 500 companies:
In 2010, 38% issued ESG reports, and 16% of those received assurance.
In 2020, 76% issued ESG reports, and 46% of those received assurance.
Meaning: More companies are reporting ESG information, and more companies are paying independent professionals to verify it.
Slide 15 — Who Provides ESG Assurance?
Financial auditors are not the only professionals providing ESG assurance.
Other providers include:
ERM
Lloyd’s
Bureau Veritas
Apex
Other specialized firms
In 2020, financial auditors provided about 19% of ESG assurance engagements.
Main lesson: ESG assurance is a growing market, but CPA firms compete with many non-accounting specialists.
Slide 16 — Relationship Between the Three Services
Think of three circles:
Assurance is the largest category.
Attestation is inside assurance.
Auditing is inside attestation.
Therefore:
Every audit is attestation and assurance, but not every assurance service is an audit.
Example:
Financial statement audit → all three.
Checking management’s sustainability claim → attestation and assurance.
Improving customer-satisfaction information → assurance, but possibly not attestation.
Slides 17–22: Management Assertions and Skepticism
Slide 17 — Sarbanes-Oxley Act of 2002
Congress passed the Sarbanes-Oxley Act, commonly called SOX, after major accounting scandals such as Enron and WorldCom.
SOX increased corporate accountability.
Most important idea: Management—not the auditor—is responsible for:
The financial reporting process
The financial statements
The company’s internal controls
The auditor checks management’s work but does not create management’s responsibility.
Slide 18 — CEO and CFO Certification
Under SOX Section 302, the CEO and CFO certify that:
They read the financial statements.
They are not aware of major false statements or missing disclosures.
They believe the statements fairly show the company’s financial condition.
For certain larger public companies called accelerated filers:
Management reports on internal controls.
Under Section 404, the auditor also reports on internal control over financial reporting.
Simple version: The CEO and CFO cannot blame the auditor by saying, “We didn’t know the financial statements were wrong.”
Slide 19 — Management’s Five Assertions
Assertions are the promises management automatically makes when it presents financial statements.
Assertion | Simple question |
|---|---|
Existence or occurrence | Is it real? |
Completeness | Did we include everything? |
Valuation or allocation | Is it recorded for the correct amount? |
Rights and obligations | Does the company own it or owe it? |
Presentation and disclosure | Is it classified and explained properly? |
Example: Inventory
Management is claiming:
The inventory really exists.
All inventory is included.
Inventory has the correct value.
The company owns the inventory.
Inventory is properly presented and disclosed.
These assertions become the auditor’s testing targets.
Slide 20 — Assertions for Transactions and Balances
Different assertions apply depending on what the auditor is testing.
Transactions
Occurrence: Did the recorded transaction actually happen?
Completeness: Were all transactions recorded?
Accuracy: Was the correct amount recorded?
Cutoff: Was it recorded in the correct period?
Classification: Was it recorded in the correct account?
Account balances
Existence: Does the asset or liability exist?
Completeness: Are all balances included?
Valuation: Is the balance correct?
Rights and obligations: Does the company own the asset or owe the liability?
Helpful exam trick
Worried something recorded is fake or overstated? Test existence/occurrence.
Worried something was left out or understated? Test completeness.
Worried December sales were recorded in January? Test cutoff.
Slide 21 — Professional Skepticism
Professional skepticism means having a questioning mind and critically evaluating evidence.
The auditor should:
Ask questions.
Obtain answers.
Verify those answers.
Investigate unusual trends.
Check whether documents are authentic.
Look for evidence that supports or contradicts management.
Important: Inquiry alone is never enough.
Management wants the company to appear successful. The auditor must independently determine whether that picture is fair.
Slide 22 — Auditors Must Be Skeptical
Professional skepticism does not mean assuming management is lying.
It means the auditor should:
Remain neutral.
Consider both supporting and contradictory evidence.
Watch for possible errors and fraud.
Evaluate whether evidence is relevant and reliable.
Refuse to accept weak or unpersuasive evidence.
Consider management’s bias and the auditor’s own bias.
Best way to remember it: Trust is not audit evidence—verify it.
Slides 23–29: CPA Firms and Different Auditors
Slide 23 — Services Offered by Public Accounting Firms
CPA firms generally offer three major service groups:
Assurance
Financial statement audits
Attestation engagements
Reviews
Compilations
Other assurance services
Tax
Preparing tax returns
Tax planning
Tax compliance
Consulting and advisory
Technology consulting
Risk consulting
Business strategy
System design and implementation
Quick assurance comparison
Audit: reasonable assurance; most testing.
Review: limited assurance; mainly questions and analytical procedures.
Compilation: organizes management’s information; no assurance.
Slides 24–25 — Prohibited Services
SOX prevents an audit firm from performing certain services for its public-company audit clients.
Examples include:
Bookkeeping
Designing financial information systems
Valuation services
Internal audit outsourcing
Management or HR services
Certain legal and investment services
Why are these prohibited?
The auditor should not make management decisions.
The auditor should not audit their own work.
Example: If the auditor creates the company’s accounting system and then audits that system, independence is weakened.
Some tax and other permitted services may be provided when the audit committee approves them in advance. The firm can also provide prohibited services to companies it does not audit.
Slide 26 — Big Four Revenue in 2021
The Big Four are:
Deloitte
EY
KPMG
PwC
The table shows that they earn money from audit, tax, and advisory services.
Deloitte earned 61% of its 2021 revenue from advisory services.
Main lesson: The Big Four are not only audit firms. They are large professional-service organizations.
Slide 27 — Big Four Revenue in 2024
Firm | Total revenue | Audit/assurance | Tax | Advisory/other |
|---|---|---|---|---|
Deloitte | $67.2B | 31% | 17% | 52% |
EY | $51.2B | 34% | 24% | 42% |
KPMG | $38.4B | 35% | 23% | 42% |
PwC | $55.4B | 35% | 23% | 42% |
What to notice: Audit is extremely important, but advisory and tax make up a large portion of Big Four revenue.
Slide 28 — Public Accounting Firm Organization
A typical career ladder is:
Staff/associate: performs detailed testing and prepares documentation.
Senior: leads daily fieldwork and reviews staff work.
Manager: manages engagements and communicates with the client.
Partner: accepts responsibility for the engagement and signs the report.
Managing partner/executive committee: leads the overall firm or office.
The firm is also separated into service lines:
Assurance
Tax
Advisory
Slide 29 — Types of Auditors
Auditor | Main job |
|---|---|
External auditor/CPA | Determine whether financial statements are reliable |
Internal auditor/CIA | Improve operations, controls, efficiency, and compliance |
Government auditor | Check compliance within governmental organizations |
Regulatory auditor | Enforce industry-specific government rules |
Examples of regulatory auditors include:
IRS auditors
Bank regulators
Insurance regulators
Difference: External auditors are independent from the client. Internal auditors usually work for or serve the organization itself.
Slides 30–36: CPA Exam and Certifications
Slide 30 — Becoming a Professional
Becoming a CPA generally involves:
Education
Passing the CPA Exam
Required work experience
State certification and licensing
Continuing to develop professional skills
Exact requirements depend on the state.
Slide 31 — CPA Exam Structure
Starting with the exam structure shown in the slides, candidates take three required core sections:
AUD: Auditing and Attestation
FAR: Financial Accounting and Reporting
REG: Taxation and Regulation
They also choose one discipline:
BAR: Business Analysis and Reporting
ISC: Information Systems and Controls
TCP: Tax Compliance and Planning
That means: three core sections + one discipline = four sections total.
Slide 32 — CPA Exam Details
According to the slide:
Each section is four hours.
Candidates must pass all four sections.
A passing score is 75.
Questions include multiple-choice questions and task-based simulations.
For AUD, the slide lists:
78 multiple-choice questions
7 task-based simulations
Each question type makes up 50% of the score
These exam details can change, so use the slide’s information for your class unless your professor says otherwise.
Slide 33 — AUD Exam Blueprint
The largest AUD content area is:
Performing procedures and obtaining audit evidence: 30–40%
Other areas include:
Assessing risk and planning: 25–35%
Ethics and professional responsibilities: 15–25%
Forming conclusions and reporting: 10–20%
Meaning: AUD is not only memorization. You must apply audit rules, evaluate evidence, identify risk, and reach conclusions.
Slides 34–36 — Other Professional Certifications
Certification | Main focus |
|---|---|
CPA | Public accounting, external auditing, financial reporting, and tax |
CISA | Auditing information systems and cybersecurity controls |
CIA | Internal auditing, operations, risk, and company controls |
CFE | Fraud prevention, detection, and investigation |
CMA | Management accounting, financial planning, and business decisions |
The slides compare their education, experience, exams, passing scores, and administering organizations.
What you should mainly remember: Know what type of career each certification supports. You probably do not need to memorize every test length or passing score unless your professor specifically says so.
Slides 37–40: Who Regulates Auditing?
Slide 37 — AICPA’s Traditional Role
Before 2003, the AICPA established auditing standards for public and private companies.
After SOX:
The PCAOB received standard-setting authority over audits of public companies.
The AICPA continued its role for nonpublic-company audits.
The AICPA continued administering the CPA Exam.
Slide 38 — PCAOB
The Public Company Accounting Oversight Board was created by SOX.
It oversees auditors of public companies by:
Registering public accounting firms
Creating auditing and independence standards
Inspecting accounting firms
Investigating violations
Disciplining and sanctioning firms
Simple version: The PCAOB watches the auditors who audit public companies.
Slides 39–40 — SEC
The Securities and Exchange Commission is a federal government agency that protects investors.
The SEC:
Oversees the PCAOB.
Requires public companies to disclose financial information.
Works to prevent securities fraud.
Requires registration statements when securities are offered to the public.
Requires audited financial statements in certain filings.
Issues financial-reporting rules, including Regulation S-X.
Easy regulatory chain
SEC oversees the securities market and PCAOB
↓
PCAOB oversees auditors of public companies
↓
CPA firms audit public companies
↓
Management prepares the financial statements
Slide 41 — End of Chapter
No new material—just the end of the presentation.
Most important things to know
Audit reduces information risk, not business risk.
Assurance → Attestation → Audit from broadest to narrowest.
Management prepares the statements; the auditor independently checks them.
Know the five assertions:
Existence/occurrence
Completeness
Valuation/allocation
Rights and obligations
Presentation and disclosure
Professional skepticism means ask, obtain evidence, and verify.
Auditors cannot make management decisions or audit their own work.
Know the difference between external, internal, governmental, and regulatory auditors.
SEC oversees the PCAOB; PCAOB oversees public-company auditors.
From your course schedule, Chapter 1 is covered on August 25 and 27, appears on Quiz 1 with Chapters 1–3, and is included in Exam 1 with Chapters 1–4.