CPA Exam Lab
Section 2: 25–35%A5

Understanding the Entity and Its Environment

Exam insight

Section 2 is 25-35% of the AUD exam, expect 8-12 MCQs per sitting on risk assessment. One pairing trips people up: you must understand internal control in every audit (AU-C 315), but you only test controls when you plan to rely on them. Candidates also forget that AU-C 315 asks you to understand the entity's information system and business processes, not just the five COSO components on their own. So when a question says 'obtaining an understanding,' think AU-C 315 risk assessment procedures: inquiry, observation, inspection, and analytical procedures.

What AICPA wants you to know

  • 1Identify the components of the entity's environment the auditor must understand
  • 2Explain the purpose of understanding internal control in risk assessment
  • 3Describe risk assessment procedures: inquiry, observation, inspection, and analytical procedures
  • 4Understand the five components of internal control (COSO framework)
  • 5Recognize how industry and regulatory factors affect audit risk
  • 6Apply the key SAS 145 changes: separate IR/CR assessment, relevant assertions, the spectrum of inherent risk, and the stand-back requirement

Patterns in this topic

The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.

Exam tip

Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.