For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeCPA®CPA AUD Practice Exam 2Question 11
    Hard1 markMultiple Choice
    Area II: Risk AssessmentAUDService OrganizationsInternal Control

    CPA · Question 11 · Area II: Risk Assessment

    An auditor is testing the operating effectiveness of a user entity's internal controls. The user entity outsources its payroll processing to a service organization. The auditor obtains a SOC 1 Type 2 report from the service organization. The report identifies several exceptions in the testing of the service organization's controls. Which of the following factors is MOST important for the user auditor to consider in determining the effect of these exceptions on the user entity's audit?

    Answer options:

    A.

    Whether the user entity has complementary user entity controls (CUECs) that mitigate the risks associated with the exceptions.

    B.

    Whether the service auditor issued a qualified or adverse opinion in the SOC 1 report.

    C.

    The number of years the service organization has been in business.

    D.

    Whether the service organization has insurance to cover potential losses.

    How to approach this question

    Understand the concept of CUECs (Complementary User Entity Controls). A SOC report is a handshake; both sides have duties.

    Full Answer

    A.Whether the user entity has complementary user entity controls (CUECs) that mitigate the risks associated with the exceptions.✓ Correct
    When exceptions are noted in a SOC 1 report, the user auditor must evaluate whether those exceptions affect the controls the user auditor intends to rely on. A key factor is whether the user entity has Complementary User Entity Controls (CUECs) - such as reviewing payroll reports - that would detect and correct errors resulting from the service organization's control failures.

    Common mistakes

    Assuming any exception in a SOC report means the control failed completely for the audit.
    Question 10All questionsQuestion 12

    Practice the full CPA AUD Practice Exam 2

    78 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01An auditor is performing an audit of a nonissuer's financial statements. During the engagement, t...HardQ02A CPA firm is auditing the financial statements of an issuer, TechGlobal Inc. The lead audit part...HardQ03An auditor is conducting an audit of a nonissuer in accordance with GAO Government Auditing Stand...HardQ04During the audit of a nonissuer, the auditor identifies a significant risk of fraud related to re...HardQ05An auditor is accepting an engagement to audit the financial statements of a new nonissuer client...Hard
    View all 78 questions →