10 AUD Practice Questions With Full Explanations

Kyle Ashcraft, CPA · 2019 CPA Exam Scores · 95 FAR · 98 BEC · 91 REG · 90 AUD

AUD is the section where every word in the question is load-bearing. There is very little arithmetic. What there is instead is precision: which assertion is being tested, which direction the procedure runs, whether the auditor ultimately obtained sufficient appropriate evidence. Change one word in a fact pattern and the answer changes with it.

That is why candidates so often narrow to two choices and then pick wrong. Both options sound reasonable. Only one matches what the procedure actually did.

Below are ten AUD questions across opinions, assertions, internal controls, the audit risk model and SOC reports. Answers are hidden behind toggles so you can attempt each one cold, and the explanations spend most of their time on why the runner-up is wrong, because on AUD that is the whole skill.

Practice in the interactive quiz first

If you would rather answer all ten in one pass and see a score before reading anything, work through the quiz, then come back for the explanations.

Or watch the walkthrough

I work through all ten in the video below, talking through the reasoning I would use under exam conditions.

Prefer the app? Watch the AUD walkthrough on YouTube.

Which opinion follows a scope limitation?

Question 1 of 10 · Forming conclusions and reporting · Difficulty 4 of 5

During an audit of Lavender Ltd., the auditor finds that the accounting records for a substantial portion of sales transactions are inadequate, preventing the acquisition of sufficient appropriate audit evidence for those transactions. The auditor would most likely choose between issuing:

  • A. A qualified opinion and an unmodified opinion with an emphasis-of-matter paragraph
  • B. An unmodified opinion with an emphasis-of-matter paragraph and an adverse opinion
  • C. An adverse opinion and a disclaimer of opinion
  • D. A disclaimer of opinion and a qualified opinion
Show the answer and explanation

D. A disclaimer of opinion and a qualified opinion.

Two questions decide every opinion question, and they must be answered in this order.

First, what kind of problem is it? Either the auditor could not get enough evidence, which is a scope limitation, or the auditor got the evidence and the financial statements are wrong, which is a misstatement. Here the records are inadequate, so the auditor cannot obtain evidence. Scope limitation.

Second, how bad is it? Material but not pervasive, or material and pervasive.

 Material, not pervasiveMaterial and pervasive
Cannot obtain evidenceQualifiedDisclaimer
Statements are misstatedQualifiedAdverse

Read the left column of that table and the answer falls out. A scope limitation gives you qualified or disclaimer, which is answer D.

The trap: answer C pairs adverse with disclaimer, which feels right because both sound severe. But adverse belongs to the bottom row. It is the response to a material and pervasive misstatement, never to missing evidence. Memorize the table as a two-by-two rather than as four separate rules and this whole question type collapses into one lookup.

What if the auditor misses the inventory observation?

Question 2 of 10 · Evidence · Difficulty 3 of 5

An auditor was engaged to audit Maple Inc. for the year ending December 31. The auditor could not attend the year-end inventory count due to timing issues, and inventory is material to the financial statements. The auditor performed alternative audit procedures and obtained sufficient appropriate audit evidence regarding the inventory balances. What opinion should the auditor consider issuing?

  • A. An unmodified opinion, because sufficient appropriate evidence was obtained through alternative procedures
  • B. A qualified opinion, due to the inability to observe the year-end inventory count
  • C. An adverse opinion, because the inventory count is a critical part of the audit
  • D. A disclaimer of opinion, because the audit was limited in scope
Show the answer and explanation

A. An unmodified opinion.

Missing a specific procedure is not itself a scope limitation. A scope limitation exists only when the auditor cannot obtain sufficient appropriate evidence by any means. Here alternative procedures worked, so the evidence requirement was satisfied and there is nothing to modify.

Alternative procedures for inventory typically include examining subsequent sales of the items, testing the client's count records against purchase and shipping documentation, and observing a physical count at a later date and rolling backwards to the year-end quantities.

The question to ask every time: did the auditor ultimately obtain sufficient appropriate evidence? If yes, the opinion is unmodified regardless of how awkward the route was. Answers B, C and D all assume the missed observation is fatal by itself, and the last sentence of the stem tells you it was not.

A wording note. "Unmodified" is the term under the AICPA standards that govern audits of nonissuers, which is what AUD tests most. "Unqualified" is the PCAOB term used for issuers. They mean the same thing, and the exam uses both depending on which framework the question sits in, so read the stem for which one applies.

Which assertion does the direction of testing address?

Question 3 of 10 · Evidence · Difficulty 2 of 5

During an audit of Henderson Corporation, the auditor traces several bills of lading to the corresponding sales invoices. What audit objective is primarily being addressed?

  • A. Ensuring that all goods dispatched have been recorded as sales
  • B. Verifying that all recorded sales are supported by shipment documents
  • C. Confirming that shipments to customers were invoiced
  • D. Checking the accuracy of inventory count and valuation
Show the answer and explanation

C. Confirming that shipments to customers were invoiced.

Direction of testing is the entire question. A bill of lading is a shipping document, evidence that something physically left the building. Starting there and tracing forward into the accounting records tests completeness: did everything that happened get recorded?

Answer B is the reverse direction. Starting from recorded sales and going back to shipping documents tests occurrence: did everything recorded actually happen? Same two documents, opposite question, different assertion.

Why C beats A, which is the harder call. Both describe completeness, and A is not a wrong idea. But the procedure as written stops at the sales invoice. It does not go on to the sales journal or the general ledger. C describes exactly where the trace ends. A describes a longer procedure that would carry through to the recorded sales figure. AUD rewards matching the answer to the procedure performed rather than to the general concept it belongs to, and a pair of choices this close is the exam testing precisely that.

The rule worth internalizing: trace forward from source documents to records for completeness, vouch backward from records to source documents for occurrence and existence.

How do you test controls over completeness of sales?

Question 4 of 10 · Risk assessment and controls · Difficulty 3 of 5

Which procedure would an auditor most likely perform to test controls related to management's assertion of the completeness of sales transactions?

  • A. Examine a sample of shipping documents and trace them to the purchase order
  • B. Review a selection of sales invoices and compare them to the shipping log
  • C. Analyze a report of prenumbered sales invoices and investigate any gaps in the sequence
  • D. Assess the consistency of sales invoice processing by checking for proper authorization
Show the answer and explanation

C. Analyze a report of prenumbered sales invoices and investigate gaps in the sequence.

Prenumbering is the classic completeness control, and the reason is mechanical. If documents are issued in an unbroken sequence, then a missing number is visible evidence that something exists but is unaccounted for. No other control makes an omission announce itself.

Note that this is a test of controls, not a substantive test. The question is whether the client's own sequence check is operating, which is why it asks about a report the client produces rather than about the transactions themselves.

Why the others fail: B runs from invoices back to shipping records, which is the occurrence direction. D tests authorization, a different assertion entirely. A traces shipping documents to purchase orders, which mixes the revenue cycle up with the purchasing cycle, since a purchase order is a document the customer sends rather than one the client's shipping generates.

How do you search for unrecorded liabilities?

Question 5 of 10 · Evidence · Difficulty 3 of 5

In searching for unrecorded liabilities at year-end, which of the following would an auditor most likely examine?

  • A. Receiving reports for items received before year-end that have no matching recorded liability
  • B. Cutoff bank statements for checks issued just after year-end
  • C. Invoices for goods received after year-end and properly recorded in the following period
  • D. Correspondence with legal counsel regarding potential lawsuits
Show the answer and explanation

A. Receiving reports for items received before year-end with no matching recorded liability.

The liability arises when the obligation is incurred, which for goods is when they are received, not when the invoice arrives or the cheque clears. So the receiving report is the document that fixes the date. If goods came in on December 28 and no payable was recorded, accounts payable is understated at year-end and the receiving report proves it.

This is a completeness test on liabilities, and it runs in the opposite direction from most of the audit. Elsewhere you worry about things being recorded that should not be. With payables you worry about things missing that should be there, because understating liabilities makes the balance sheet look better.

Why the others fail: C describes goods received after year-end, which correctly belong to the following period, so there is nothing unrecorded about them. D goes to contingencies, a different problem entirely. B is the closest miss: examining subsequent disbursements is a genuine procedure in this search, but the phrasing here points at cutoff testing of cash rather than at identifying obligations that existed at year-end.

What makes a payroll control weak?

Question 6 of 10 · Risk assessment and controls · Difficulty 2 of 5

Which scenario most likely represents a weakness in an entity's internal controls over payroll?

  • A. Unclaimed payroll checks are stored in a secure location by the treasurer
  • B. The payroll department sends prepared checks directly to the treasurer for signing
  • C. Human resources informs payroll about terminations, but there is no cross-verification process
  • D. The employee who distributes payroll checks is also responsible for updating payroll records, including hours worked and rates of pay
Show the answer and explanation

D.

One person holds both custody of the assets and record-keeping over them. That combination is the definition of a segregation of duties failure, because it lets someone both commit a fraud and conceal it without needing anyone else's cooperation.

Work the scheme through and you can see why it is the worst of the four. That employee adds a fictitious employee to the payroll records, sets a pay rate, generates the cheque, personally distributes it and takes it, then adjusts the records so the totals reconcile. Nothing about it requires a second party.

C is a real weakness too, and worth understanding. No cross-verification of terminations means a departed employee could stay on the payroll. But that is a monitoring gap that needs either an error or a separate person's dishonesty to become a loss. D hands one person the complete kit. When two answers are both weaknesses, AUD wants the one where a single individual can execute and conceal the whole thing.

A and B are controls working properly. The treasurer safeguarding unclaimed cheques keeps custody away from payroll, and routing cheques to the treasurer for signature separates preparation from authorization.

What does it mean to assess control risk too low?

Question 7 of 10 · Risk assessment and controls · Difficulty 3 of 5

If an auditor erroneously assesses control risk as too low, what is the most likely reason for the incorrect assessment?

  • A. The auditor overestimates the operating effectiveness of the client's control activity based on the sample results
  • B. The auditor underestimates the operating effectiveness of the client's control activity
  • C. The auditor incorrectly assumes that the control activity is not relevant
  • D. The auditor incorrectly anticipates that the control activity will significantly reduce the necessity for substantive testing
Show the answer and explanation

A.

Untangle the double negative first, which is where this question does its damage. Low control risk means the auditor believes the controls are good. Assessing control risk too low therefore means believing the controls are better than they are. So the underlying error is overestimating their effectiveness.

Answer B says the opposite and is the answer most people land on, because "too low" and "underestimate" feel like they belong together. They do not. The thing assessed too low is the risk; the thing overestimated is the control.

This usually comes from sampling. The sample happened to contain fewer deviations than the population really has, and the auditor concludes the control works better than it does.

Why it matters more than the mirror-image error. Assessing control risk too low leads to too little substantive testing, so a material misstatement can go undetected. That is an effectiveness failure and it is the one the standards care about. Assessing it too high leads to more testing than necessary, which costs money but does not threaten the opinion. Efficiency problem, not an effectiveness one.

What do you do when control risk goes up?

Question 8 of 10 · Risk assessment and controls · Difficulty 3 of 5

An auditor finds that certain key control activities are not functioning as expected and increases the assessed level of control risk. As a result, which of the following would the auditor most likely increase?

  • A. Extent of tests of details
  • B. Level of detection risk
  • C. Level of inherent risk
  • D. Extent of tests of controls
Show the answer and explanation

A. Extent of tests of details.

Run it through the audit risk model. Audit risk is held at an acceptably low level and is not something the auditor moves in response to findings. Inherent and control risk belong to the client. Detection risk is the only lever the auditor actually controls.

So if control risk rises and audit risk must stay fixed, detection risk has to come down. You lower detection risk by doing more substantive work, which means more tests of details, larger samples, and testing closer to year-end rather than at an interim date.

Why B is wrong, and it is the tempting one. Detection risk changes here, but it moves down, not up. Raising it would mean accepting a greater chance of missing a misstatement at exactly the moment you have learned the client's controls are weaker than you thought.

Why D is wrong is the more interesting point. Having concluded the controls are not operating, you would test them less, not more. There is no reason to keep gathering evidence about controls you have already decided not to rely on. Testing them further buys nothing.

C is out because inherent risk is a property of the account and its environment. The auditor assesses it; the auditor does not set it.

Which SOC report answers the question?

Question 9 of 10 · Evidence and reporting · Difficulty 4 of 5

A publicly traded company requests an external audit of its technology service provider's system to gain assurance about the effectiveness of controls related to financial reporting. Which report satisfies that need, covering both the suitability of design and the operating effectiveness of the controls?

  • A. SOC 1 Type 1
  • B. SOC 2 Type 1
  • C. SOC 1 Type 2
  • D. SOC 2 Type 2
Show the answer and explanation

C. SOC 1 Type 2.

Two independent choices, and every SOC question is built this way. Get both right and the answer is forced.

ChoiceOption 1Option 2
Which controls?SOC 1: controls relevant to the user's financial reportingSOC 2: security, availability, processing integrity, confidentiality, privacy
Design or operation?Type 1: design only, at a point in timeType 2: design and operating effectiveness, over a period

The stem says financial reporting, which gives you SOC 1. It says operating effectiveness, which gives you Type 2.

The trap is the word "technology." A technology service provider sounds like it calls for SOC 2, and that pull is deliberate. The report is chosen by what the user needs assurance about, not by what industry the service organization operates in. A payroll processor, a data centre and a claims administrator can all produce SOC 1 reports, because what matters is whether their controls affect their customers' financial statements.

Also note who reads each one. SOC 1 is restricted to the user entity and its auditors. SOC 2 is restricted but has a wider audience. SOC 3 covers the same trust services criteria as SOC 2 and is the only one intended for general public distribution.

What does good segregation of duties look like?

Question 10 of 10 · Risk assessment and controls · Difficulty 2 of 5

Which scenario demonstrates effective segregation of duties?

  • A. The cashier who handles cash receipts also reconciles the cash ledger at the end of the day
  • B. An accounts payable clerk prepares checks but does not have the authority to sign them
  • C. The inventory manager is responsible for both ordering inventory and receiving goods
  • D. A salesperson records their own sales transactions and adjusts customer account balances
Show the answer and explanation

B.

Preparation is separated from authorization. The clerk can produce the cheque but cannot release the money, so a fraudulent disbursement needs a second person to sign off on it.

Four duties should sit with four different people wherever the organization is large enough to allow it:

AuthorizationApproving the transaction
CustodyHolding the asset
Record-keepingEntering it in the books
ReconciliationIndependently checking that records agree to the asset

Test each wrong answer against that list. A combines custody with reconciliation, so the person holding the cash also confirms the cash is right. C combines authorization with custody, so the person ordering the goods also confirms they arrived. D combines record-keeping with authorization, so the salesperson records a sale and can then write it off.

When you cannot separate them, which is the reality in small entities, the answer is compensating controls: owner review of bank statements, mandatory holidays, rotation of duties. The exam does test that segregation is not always achievable, and it wants you to know what you substitute when it is not.

Where does Maxwell CPA Review fit?

Concessions first. If you want the largest question bank available, that goes to Gleim or UWorld. If your firm sponsors a course, it is usually Becker, and there is no reason to decline something already paid for. If you want adaptive software that scores your readiness, Surgent does that better than I do.

What Maxwell CPA Review does is different, and AUD is where it shows most clearly. Every other option in this category answers a shortage: more questions, longer explanations, more visuals. Maxwell answers a surplus. Doing another thousand AUD questions does not help if you keep narrowing to the same two choices and picking wrong, because the problem is not coverage. It is that nobody explained why the runner-up loses.

Here is what is in the AUD section:

Video lessons6 hours
Practice MCQs750
Task-based simulations32
Textbook190 pages
Study outlines60 pages
Also includedFinal review and a full simulated exam

Across the whole course: 50 hours of video content, 5,000 practice MCQs and 150 task-based simulations, covering all six sections, FAR, AUD, REG, BAR, ISC and TCP, with no discipline upcharge. Built to the current AICPA Blueprint, with every lecture, textbook and outline created by one CPA who scored 90 or above on every section.

Best for candidates who keep landing on the second-best answer: Maxwell CPA Review, with bite-sized lessons focused on the concepts that matter most, at $49 per month, billed monthly, cancel anytime.

Use it as your primary course. Use it to retake a section you failed. Use it alongside what you already bought.

Start free with CPA 101

Practice all 25 of the 2026 AICPA released MCQs, plus a free study outline. FAR, AUD and REG tracks available. No credit card required.

Start CPA 101 free

Frequently asked questions

When does an auditor issue a qualified opinion rather than a disclaimer?

Both respond to an inability to obtain sufficient appropriate evidence. The difference is severity: a qualified opinion when the possible effects are material but not pervasive, a disclaimer when they are material and pervasive. Adverse opinions belong to a different row, responding to material and pervasive misstatements rather than to missing evidence.

What is the difference between completeness and existence?

Completeness starts with what happened and checks that it was recorded, so you trace forward from source documents into the records. Existence and occurrence start with what was recorded and check that it happened, so you vouch backward from the records to source documents. Same two documents, opposite direction, different assertion.

What is the difference between a SOC 1 and a SOC 2 report?

SOC 1 covers controls at a service organization that are relevant to the user entity's financial reporting. SOC 2 covers the trust services criteria: security, availability, processing integrity, confidentiality and privacy. Type 1 addresses design at a point in time and Type 2 addresses design plus operating effectiveness over a period.

What happens if control risk is assessed too low?

The auditor relies too heavily on the client's controls and performs too little substantive testing, which raises the chance of failing to detect a material misstatement. That is an effectiveness failure. Assessing control risk too high causes unnecessary work, which is only an efficiency problem.

Which four duties should be segregated?

Authorization, custody, record-keeping and reconciliation. Where an organization is too small to separate all four, compensating controls take their place, such as owner review of bank statements, mandatory holidays and rotation of duties.

Does missing the inventory observation require a modified opinion?

No, not automatically. If alternative procedures produce sufficient appropriate evidence about the inventory balances, an unmodified opinion is appropriate. A scope limitation exists only when the evidence cannot be obtained by any means.

Can I use Maxwell CPA Review alongside Becker, UWorld, Gleim or Surgent?

Yes. It is built to the current AICPA Blueprint and covers the same sections, so it works alongside a course you already own. Most candidates use it for the video lessons and outlines and keep their existing question bank.

Ready for more than ten questions?

Start with the 2026 AICPA released questions and the free study outline, and see whether the explanations work the way you need them to.

Start CPA 101 free

Kyle Ashcraft, CPA scored 90 or above on every section of the CPA exam in 2019, including a 90 on AUD and a 95 on FAR. He is the founder and sole instructor of Maxwell CPA Review, where he creates every lecture, textbook and study outline himself.

Reach him at MaxwellCPAreview@gmail.com.

Previous
Previous

10 REG Practice Questions With Full Explanations

Next
Next

How to Answer 10 High-Yield FAR Questions (With Full Explanations)