How an Audit Works, Part 1: Acceptance, Planning and Documentation
Kyle Ashcraft, CPA · 2019 CPA Exam Scores · 95 FAR · 98 BEC · 91 REG · 90 AUD
The most common way to study AUD badly is to memorize rules one at a time. There are hundreds of them and they look arbitrary in isolation, so the memorizing never ends and none of it sticks. Learn the order the audit actually happens in and most of those rules stop being rules. They become the obvious answer to a question the previous step just raised.
This is part one of four. It covers everything before the auditors test a single balance: deciding whether to take the client at all, what management has to agree to, the engagement letter, documentation, planning, and who else the auditor is allowed to lean on.
AUD 101: the complete audit process
- Client acceptance, engagement letter, documentation and planning (you are here)
- Audit risk, materiality and internal controls
- Substantive testing: cash, receivables and revenue
- Audit reports and opinions
Prefer the app? Watch part one on YouTube.
In this article
Why does a company need to be audited?
A company prepares its own financial statements and hands them to the people who rely on them: investors, lenders, regulators. The problem states itself. If the company writes the numbers, what stops it from inflating revenue or burying a liability?
That gap is the entire reason external auditors exist. The company pays an independent firm to test the accounts and issue an opinion on whether the statements are fairly presented. Once that opinion exists, users have a reason to trust numbers the company produced about itself.
The one thing to carry into every AUD question: the financial statements belong to management. The auditor gives an opinion on them. Preparing them, and presenting them fairly, is never the auditor's job.
That single distinction resolves a surprising share of exam questions on its own, and it also explains why so many of the rules below exist. If management owns the statements, then the auditor needs management to admit that in writing, needs access to everything management holds, and needs to stay independent of the people producing the numbers.
How does a firm decide whether to accept a client?
Willingness to pay is not the test. Client acceptance is the first decision the firm makes and the exam treats it as one.
The governing concern is management integrity. The audit runs on information management provides. If management is not honest, every subsequent procedure is built on a compromised foundation, and no amount of testing repairs that.
Beyond integrity, the firm asks three practical questions:
| Competence | Does the firm know this industry? Does the engagement need specialist knowledge the firm lacks? |
|---|---|
| Resources | Is there staff available for the timeline? Will component auditors be needed for other locations? |
| Timing | Can the firm finish within the client's reporting deadline? |
The trap you will see: a scenario pairing a large fee with a red flag about management's integrity. The answer is to decline. Fee size never outweighs integrity, and the exam constructs these questions specifically to check whether you will trade one for the other.
What must management agree to before the audit begins?
The auditor cannot accept an engagement until two preconditions are satisfied.
The first is that the financial reporting framework is acceptable. If a client proposes to report on a basis the auditor cannot audit against, there is nothing to give an opinion on.
The second is management's written acknowledgement of three responsibilities. These reappear in the engagement letter, the audit report and the management representation letter, so learning them once pays off repeatedly.
| Responsibility | What it means |
|---|---|
| Preparation and fair presentation | Management prepares the statements in accordance with the applicable framework and presents them fairly |
| Internal control | Management designs, implements and maintains the controls needed to prevent and detect error and fraud |
| Access | Management gives the auditor all records, documentation and personnel the audit requires |
The internal control wording is worth slowing down on, because the three verbs are tested separately. Design is building the process. Implementation is actually doing it rather than merely documenting it. Maintenance is updating it as the business changes.
What goes in the engagement letter?
The engagement letter is the contract. The auditor writes it, management signs and returns it, and only then does the audit properly begin.
| Included | Not included |
|---|---|
| Management's responsibilities | Materiality levels |
| The auditor's responsibilities | The specific procedures planned |
| Objective and scope of the audit | Sample sizes |
| The applicable financial reporting framework | Anything that would let management game the audit |
| Expected form and content of the reports | |
| That the audit gives reasonable, not absolute, assurance | |
| Fees, in most cases |
The right-hand column is where the exam concentrates, and there is one reason behind all of it. Suppose the letter disclosed that materiality was set at $100,000. Management would then know precisely how large a misstatement it could make without consequence. Every item in that column is excluded on the same logic: nothing goes to management that would let management design around the audit.
Reasonable assurance is doing real work in that letter. It is a high level of assurance and it is deliberately not absolute, because sampling, judgment and the possibility of collusion mean some misstatements can escape a properly performed audit. That admission is the seed of audit risk, which is where part two starts.
What is audit documentation and who owns it?
Audit documentation, also called working papers, is any record of the work performed: procedures run, evidence examined, conclusions reached. A working paper can be as ordinary as a spreadsheet.
Two facts about ownership and purpose.
The working papers belong to the auditor. Not to the client, even though the client paid for the audit. The firm has no obligation to hand them over.
They serve two purposes: supporting the opinion, and demonstrating that the audit was conducted in accordance with the standards. The second matters more than candidates expect. A procedure performed but not documented is, for review and inspection purposes, a procedure not performed.
Retention and completion deadlines
These differ between nonissuers and issuers, and the exam tests the split.
| Nonissuers (AICPA) | Issuers (PCAOB) | |
|---|---|---|
| Assemble the final file within | 60 days of the report release date | 45 days of the report release date |
| Retain documentation for | At least 5 years | At least 7 years |
After the file is assembled, documentation can be added but nothing can be deleted, and any addition must record who made it, when and why.
What makes audit evidence sufficient and appropriate?
Two words that run through the entire section, and they measure different things.
| Term | Measures | How the auditor changes it |
|---|---|---|
| Sufficient | Quantity. Is there enough? | Extent of testing |
| Appropriate | Quality. Is it relevant and reliable? | Nature and timing of procedures |
The auditor has exactly three levers, and the standards always name them in this order: nature, timing and extent.
| Nature | What type of procedure. A search for unrecorded liabilities is a different instrument from a confirmation, and each answers a different assertion. |
|---|---|
| Timing | When it is performed. Testing at year-end is more reliable for a period-end balance than interim testing, which needs roll-forward work to cover the remaining months. |
| Extent | How much. Forty invoices give more evidence than twenty. |
Notice how the levers pair with the two evidence words. Extent buys quantity. Nature and timing buy quality. When a question asks how the auditor should respond to increased risk, the answer is always some combination of these three, which is why recognizing the pattern is worth more than memorizing the individual responses.
Start free with CPA 101
Practice all 25 of the 2026 AICPA released MCQs, plus a free study outline. FAR, AUD and REG tracks available. No credit card required.
What happens during audit planning?
Planning produces two documents, and the distinction between them is straightforward once you see the altitude difference.
| Audit strategy | Audit plan |
|---|---|
| Objectives of the engagement | Specific procedures for each account and cycle |
| Staffing and resources | Which assertion each procedure addresses |
| Budgeted hours and timeline | Sample sizes and testing approach |
| Big-picture risk areas | How each planned response links back to an assessed risk |
Strategy is the shape of the engagement. The plan is the instruction set.
When are analytical procedures required?
Analytical procedures are comparisons: trend analysis, ratios, expectations checked against actuals. They appear at three points in the audit, and they are required at two of them.
| Phase | Purpose | Required? |
|---|---|---|
| Planning | Understand the client and locate risk | Yes |
| Substantive testing | Gather evidence on specific balances | No, the auditor's choice |
| Overall final review | Ask whether the statements make sense as a whole | Yes |
The distinction the exam wants: planning analytics are a risk assessment tool and are mandatory. Substantive analytical procedures are an evidence-gathering technique and are optional, chosen when they will be more efficient than tests of details. Same technique, different job, different rule. Candidates who learn them as one thing lose points on both.
Understanding the business
Planning also means learning how this client actually operates: its business model, its accounting choices, what normal looks like in its industry. Auditors get there by touring facilities, reading industry publications and prior-year statements, and interviewing staff.
The reason is that an auditor who does not know what normal looks like cannot recognize abnormal. Every analytical procedure depends on having an expectation to compare against, and the expectation comes from this work.
What must the auditor understand about internal controls?
Internal controls are the processes a company uses to catch errors and deter fraud. Three separate concepts attach to them, the exam tests them separately, and confusing them is among the most common ways to lose easy AUD points.
| Concept | The question it asks | Required? |
|---|---|---|
| Design | Does this control exist, and is it capable of preventing or detecting misstatement? | Yes, every audit |
| Implementation | Is anyone actually doing it? | Yes, every audit |
| Operating effectiveness | Is it working well enough that we can rely on it and test less elsewhere? | Generally the auditor's choice |
Design and implementation are never optional. Testing operating effectiveness is a strategic decision: test the controls and rely on them, doing less substantive work, or skip the testing and do more substantive work instead. Either route is acceptable. It is a trade, not a requirement.
One exception worth knowing. In an integrated audit of internal control over financial reporting, which applies to certain issuers, the auditor must test operating effectiveness. There the controls are themselves a subject of the opinion rather than merely a means of reducing substantive work. So the honest answer to "is testing controls required" is: not in a financial statement audit, but yes in an integrated audit.
What does a successor auditor owe the predecessor?
When a company changes firms, the incoming firm is the successor and the outgoing one the predecessor. Before accepting, the successor is required to attempt communication with the predecessor.
The purpose is to find out why the company changed firms. A disagreement over accounting principles, a dispute about scope, or a concern about management's integrity are all things the successor would rather learn now than in month three.
| The obligation is to attempt | Not to succeed. If the predecessor does not respond, the successor may still accept, having considered what the silence implies. |
|---|---|
| Client permission is required | Confidentiality binds the predecessor. The successor asks management to authorize a full response. |
| Refusal is evidence | If management will not grant permission, the successor should ask why and weigh that in the acceptance decision. |
That last row is the one candidates skip. A refusal is not merely an administrative dead end. It is information about the client, arriving during precisely the phase where information about the client is what you are gathering.
Who else can the auditor rely on?
The external auditor does not work alone. Three groups can contribute, each with a different independence position and a different limit.
Internal auditors
Internal auditors are employees of the company being audited. They do audit-type work inside the organization all year, often in anticipation of the external audit.
They can help, with a real constraint: they are not independent, because they work for the client. Their involvement should be confined to areas of low complexity and low subjectivity. Significant estimates, judgmental areas and high-risk balances stay with the external team.
Before using their work at all, the external auditor evaluates three things: competence, objectivity, and whether the internal audit function applies a systematic and disciplined approach. That third criterion is frequently forgotten and just as frequently tested.
Specialists
A specialist has expertise outside accounting and auditing, such as an appraiser valuing a complex investment or an actuary measuring a pension obligation.
The distinction to hold onto is whose specialist it is. An auditor's specialist is engaged by the audit firm to help obtain evidence. A management's specialist is engaged by the client to help prepare the statements, and the auditor then evaluates that person's work as evidence rather than directing it.
Either way, responsibility does not move. The auditor evaluates the specialist's competence and objectivity, understands the methods and assumptions used, and assesses whether the findings are reasonable. The auditor does not refer to the specialist in the audit report, unless the reference is relevant to understanding a modification of the opinion, because a reference could read as dividing responsibility that has not been divided.
Component auditors
Where a parent has subsidiaries in different places, the group auditor may engage other firms as component auditors to audit individual components.
Materiality is the part most explanations get wrong. Component auditors do not set their own materiality. The group engagement team determines both group materiality and component materiality, and component materiality is deliberately set below group materiality so that uncorrected misstatements across several components cannot aggregate into something material at group level. Handing each component auditor its own independent threshold would defeat the arithmetic the whole design rests on.
The group auditor also chooses between two reporting positions:
| Position | What it means |
|---|---|
| Assume responsibility | No reference to the component auditor in the report. The group auditor is fully responsible and must be sufficiently involved in that component's work. |
| Make reference | The report names the division of responsibility and identifies the magnitude of the portion audited by others. |
| Group | Independent? | Key limit |
|---|---|---|
| Internal auditors | No, employees of the client | Low-complexity, low-subjectivity work only |
| Specialists | Auditor's specialist yes; management's specialist is the client's | Auditor still evaluates methods, assumptions and results |
| Component auditors | Yes, separate firms | Group team sets component materiality and either assumes responsibility or makes reference |
One rule ties all three together: the external auditor signing the opinion is always ultimately responsible. Others can perform work. Nobody else can absorb the responsibility.
Where does Maxwell CPA Review fit?
Concessions first. If you want the largest question bank available, that goes to Gleim or UWorld. If your firm sponsors a course, it is usually Becker, and there is no reason to decline something already paid for. If you want adaptive software that scores your readiness, Surgent does that better than I do.
What Maxwell CPA Review does is different, and this article is a sample of it. Every other option in this category answers a shortage: more questions, longer explanations, more visuals. Maxwell answers a surplus. AUD has hundreds of individual rules, and the reason candidates drown is that most courses present them as hundreds of individual rules. Teach the sequence and most of them become predictable.
Here is what is in the AUD section:
| Video lessons | 6 hours |
|---|---|
| Practice MCQs | 750 |
| Task-based simulations | 32 |
| Textbook | 190 pages |
| Study outlines | 60 pages |
| Also included | Final review and a full simulated exam |
Across the whole course: 50 hours of video content, 5,000 practice MCQs and 150 task-based simulations, covering all six sections, FAR, AUD, REG, BAR, ISC and TCP, with no discipline upcharge. Built to the current AICPA Blueprint, with every lecture, textbook and outline created by one CPA who scored 90 or above on every section.
Best for candidates who want the process before the rules: Maxwell CPA Review, with bite-sized lessons focused on the concepts that matter most, at $49 per month, billed monthly, cancel anytime.
Use it as your primary course. Use it to retake a section you failed. Use it alongside what you already bought.
Frequently asked questions
What is the purpose of the engagement letter?
It is the written agreement setting the terms of the audit before work begins, covering the objective and scope, management's and the auditor's responsibilities, the applicable financial reporting framework, the expected reports, and the fact that the audit provides reasonable rather than absolute assurance. It does not disclose materiality levels or the specific procedures planned.
What is the difference between sufficient and appropriate audit evidence?
Sufficient is quantity, appropriate is quality. The auditor increases sufficiency by increasing the extent of testing, and improves appropriateness by changing the nature and timing of procedures.
Is the auditor required to test internal controls on every audit?
Understanding the design and implementation of internal controls is required on every audit. Testing operating effectiveness is generally the auditor's choice in a financial statement audit, traded against how much substantive work is needed. In an integrated audit of internal control over financial reporting, testing operating effectiveness is required.
Who sets materiality in a group audit?
The group engagement team, for both group materiality and component materiality. Component materiality is set below group materiality so that uncorrected misstatements across components cannot aggregate into a material amount at group level. Component auditors do not set their own thresholds.
What happens if the predecessor auditor does not respond?
The successor is only required to attempt communication. If there is no response, the successor may still accept the engagement, having considered what that implies. If management refuses to authorize the predecessor to respond, the successor should ask why and weigh that heavily.
Who is responsible when a specialist performs work for the audit?
The external auditor. The auditor evaluates the specialist's competence and objectivity, understands the methods and assumptions, and assesses whether the findings are reasonable. The audit report does not refer to the specialist unless that reference is relevant to understanding a modification of the opinion.
How long must audit documentation be retained?
At least five years for nonissuers under AICPA standards and at least seven years for issuers under PCAOB standards. The final file is assembled within 60 days of the report release date for nonissuers and 45 days for issuers. After assembly, documentation may be added but not removed.
Ready for part two?
Part two covers audit risk, materiality and testing internal controls. In the meantime, start with the 2026 AICPA released questions and the free study outline.
Kyle Ashcraft, CPA scored 90 or above on every section of the CPA exam in 2019, including a 90 on AUD and a 95 on FAR. He is the founder and sole instructor of Maxwell CPA Review, where he creates every lecture, textbook and study outline himself.
Reach him at MaxwellCPAreview@gmail.com.
Explore the Complete AUD 101 Series
The foundation of the audit, from engagement letters to initial strategy.
Master the audit risk formula, materiality, and the framework that drives procedures.
A complete walkthrough of the balance sheet, sampling, and the legal letter.
Concluding the audit, handling subsequent events, and issuing the final report.
