Bank: Principles of
Auditing and Assurance
Services (Whittington)
PART 0: THE TABLE OF CONTENTS
● PART I: THE PREVIEW
○ The Critical Axioms Cheat Sheet
● PART II: THE ELITE TEST BANK
○ Tier 1: Foundational Syntax & Application (Questions 1–10)
○ Tier 2: Complex Application & Simulation (Questions 11–20)
○ Tier 3: Grandmaster Synthesis (Questions 21–30)
PART I: THE PREVIEW
Mastering this Elite Test Bank translates directly to executive-level audit competence by forging
the cognitive stamina required to navigate complex global reporting frameworks. The
assessment replaces rote memorization with a surgical dissection of risk assessment, auditor
liability, and quality control at the highest echelons of public accounting.
The "Critical Axioms" Cheat Sheet:
● The SAS 145 Paradigm: The auditor must separately assess inherent risk and control
risk. If the auditor does not test the operating effectiveness of controls, control risk must
be assessed at the absolute maximum.
● The Liability Triad: The perimeter of third-party liability is expanding. It encompasses
Ultramares (known primary beneficiary/privity), Restatement of Torts (foreseen users),
and Rosenblum (foreseeable users).
● The QC 1000 Mandate: Quality Control requires a dynamic, risk-based framework
comprising eight specific components. It emphasizes accountability, continuous
remediation, and an annual evaluation reported directly to the PCAOB.
● The Unrecorded Liability Trap: The primary risk in the expenditure cycle is
understatement. The search for unrecorded liabilities MUST focus on examining
subsequent cash disbursements and unmatched receiving reports to validate the
completeness assertion.
● The PCAOB Inspection Focus: Regulatory inspectors consistently cite deficiencies in
Management Review Controls (MRCs), fixed asset existence/impairment evaluations
under ASC 360, and the failure to independently challenge management's qualitative
, assumptions.
PART II: THE ELITE TEST BANK
Tier 1: Foundational Syntax & Application (Questions 1–10)
Q1: A mid-sized manufacturing client provides its audited financial statements to a local bank to
secure a commercial loan. The audit engagement team was entirely unaware that the client
intended to use the financial statements for this specific loan. The bank suffers a massive
financial loss due to undetected material misstatements caused by the auditor’s ordinary
negligence. Based on the principles of Common Law Auditor Liability, under which judicial
approach is the auditor MOST LIKELY to successfully defend against the bank's lawsuit? A)
The Restatement of Torts approach B) The Rosenblum approach C) The Ultramares approach
D) The Securities Exchange Act of 1934 framework
● Answer: C (The Ultramares approach)
● Distractor Analysis:
○ A is incorrect: The Restatement of Torts approach expands liability to foreseen third
parties. Because the auditor did not know the client's intent to distribute the report
to this specific bank, they might avoid liability here, but Ultramares is the strictest
and therefore the most absolute defense against unknown third parties.
○ B is incorrect: The Rosenblum approach holds auditors liable to all foreseeable third
parties for ordinary negligence. The bank is a highly foreseeable user in the normal
course of business, meaning the auditor would likely lose the lawsuit under this
progressive standard.
○ D is incorrect: This is a common law scenario regarding a private commercial loan,
not a statutory law scenario involving publicly traded securities governed by the
1934 Act, which requires proof of scienter.
The Mentor's Analysis: The evolution of auditor liability hinges entirely on the perimeter of
privity. The Ultramares doctrine, established by Justice Cardozo in 1931, strictly limits liability for
ordinary negligence to parties in direct privity of contract or known primary beneficiaries. When
an auditor is unaware of a third party, Ultramares serves as an impenetrable shield against
ordinary negligence claims, preventing liability in an indeterminate amount to an indeterminate
class.
Judicial Approach Beneficiary Perimeter Standard of Liability
Ultramares Known Primary Beneficiary Ordinary Negligence
(Privity)
Restatement of Torts Foreseen Third Parties Ordinary Negligence
(Specific group)
Rosenblum Foreseeable Third Parties Ordinary Negligence
(General public)
Professional/Academic Intuition: Under the Ultramares doctrine, absent fraud or gross
negligence, a strict lack of privity is an absolute defense against unknown third-party
claims.
Q2: During the planning phase of a financial statement audit under AICPA Statement on
Auditing Standards No. 145 (SAS 145), the engagement team decides it will be highly inefficient
to test the operating effectiveness of the client's internal controls over payroll. Based on the
principles of AU-C Section 315, which action is the auditor REQUIRED to take? A) Assess the
, combined risk of material misstatement as low to minimize substantive testing and reduce audit
fatigue. B) Assess control risk at the maximum level so the risk of material misstatement equals
the assessment of inherent risk. C) Document the absence of a test of controls as a significant
deficiency in internal control over financial reporting. D) Perform substantive procedures only for
those relevant assertions where inherent risk is assessed at the maximum level.
● Answer: B (Assess control risk at the maximum level so the risk of material misstatement
equals the assessment of inherent risk.)
● Distractor Analysis:
○ A is incorrect: If controls are not tested for operating effectiveness, the auditor
cannot rely on them to lower the combined risk of material misstatement.
○ C is incorrect: Deciding not to test controls for audit efficiency is a valid strategic
choice; it does not inherently indicate that a significant deficiency or material
weakness exists within the client's internal systems.
○ D is incorrect: SAS 145 includes a conforming amendment requiring substantive
procedures for each relevant assertion of each significant class of transactions,
regardless of the assessed level of control risk.
The Mentor's Analysis: SAS 145 explicitly severed the legacy practice of utilizing a single,
combined risk assessment. The standard now mandates that the auditor must separately
assess inherent risk and control risk. If the auditor chooses not to test the operating
effectiveness of controls, they cannot mathematically or logically reduce the risk assessment;
control risk defaults to the absolute maximum. Professional/Academic Intuition: Without
empirical evidence proving control effectiveness, control risk is unequivocally maximum,
leaving inherent risk to dictate the entirety of the substantive testing strategy.
Q3: A PCAOB-registered firm is restructuring its internal governance to comply with QC 1000, A
Firm's System of Quality Control. The firm has historically utilized static, standardized checklists
provided by a third-party vendor to monitor engagement quality. Based on the principles of QC
1000, which structural change MUST the firm implement? A) Establish a continuous, risk-based
framework that mandates an annual evaluation of the quality control system, certified by key
firm personnel. B) Replace its internal audit partner with an external auditor from a competing
firm to ensure complete objectivity in all quality monitoring activities. C) Rescind all quality
control policies regarding non-public audits, as QC 1000 applies strictly to the audits of
international subsidiaries and broker-dealers. D) Eliminate the firm's ethics and independence
manual, deferring entirely to the AICPA's Code of Professional Conduct to avoid conflicting
interpretations.
● Answer: A (Establish a continuous, risk-based framework that mandates an annual
evaluation of the quality control system, certified by key firm personnel.)
● Distractor Analysis:
○ B is incorrect: While firms auditing over 100 issuers need an External Quality
Control Function (EQCF), it does not require replacing internal partners with
competing firm auditors for routine monitoring.
○ C is incorrect: The standard applies comprehensively to the firm's QC system for all
engagements performed under PCAOB standards, not just international
subsidiaries.
○ D is incorrect: QC 1000 heavily emphasizes a culture of integrity and
independence, requiring the firm to maintain and enforce its own rigorous ethics
framework (including EI 1000) rather than deferring entirely to external bodies.
The Mentor's Analysis: QC 1000 replaces the outdated, static interim standards (like QC 20)
with a dynamic, risk-based ecosystem. It fundamentally forces firms to actively identify quality