← All CPA Flashcard Decks

Regulatory Compliance & Standards Flashcards

7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Standards flashcards as text
  1. Under the AICPA Code of Professional Conduct, which of the following is an example of a 'self-review threat' to independence?

    Answer: A CPA audits financial statements that the firm prepared

    A self-review threat arises when a CPA audits work (e.g., financial statements) that the same firm prepared, creating risk of not critically evaluating their own work.

  2. Which of the following best describes the purpose of the COSO Internal Control—Integrated Framework?

    Answer: To provide a framework for designing, implementing, and evaluating internal controls

    The COSO framework provides guidance for organizations to design and evaluate internal control systems across five integrated components.

  3. A CPA discovers during an audit that an employee has embezzled funds. Under AU-C 265, this should be communicated to:

    Answer: Those charged with governance and appropriate management

    AU-C 265 requires significant deficiencies and material weaknesses — including fraud — to be communicated in writing to those charged with governance and management.

  4. Under IRC Section 7216, a tax return preparer who discloses tax return information without client consent may face:

    Answer: Criminal penalties including fines up to $1,000 and up to 1 year in prison

    IRC Section 7216 makes unauthorized disclosure of tax return information a criminal offense with fines up to $1,000 and/or up to 1 year imprisonment.

  5. Which SEC rule requires the CEO and CFO of a public company to personally certify the accuracy of annual and quarterly reports?

    Answer: SOX Section 302

    SOX Section 302 requires CEOs and CFOs to personally certify that periodic reports are accurate and that they have evaluated and disclosed material weaknesses in disclosure controls.

  6. Under GAAS, which of the following represents the highest level of risk the auditor considers when planning an audit?

    Answer: Inherent risk

    Inherent risk is the susceptibility of an assertion to material misstatement before considering internal controls, and represents the base-level risk the auditor must evaluate.

  7. The FinCEN Customer Due Diligence (CDD) Rule primarily requires financial institutions to identify and verify which of the following?

    Answer: Beneficial owners who own 25% or more of legal entity customers

    The FinCEN CDD Rule requires financial institutions to identify and verify the identity of beneficial owners who hold 25% or more ownership in legal entity customers.