AUD exam skill

Issuer vs. nonissuer audits: choose the governing standards

Use the entity and engagement facts to select PCAOB or AICPA standards before analyzing ICFR, communications, independence, or reporting.

The decision that earns the point

Identify the engagement facts and governing framework

PCAOB standards govern covered audit reports for public companies and other issuers and for broker-dealers. AICPA Statements on Auditing Standards govern nonissuer audits that are not otherwise required to follow PCAOB standards. The question's entity and engagement facts, not company size alone, select the authority.

Exam use

AUD explicitly labels issuer and nonissuer questions when their requirements differ and can test authority, terminology, communications, procedures, independence, integrated-audit facts, and report form.

Check the official exam scope

Your scratch-paper plan

Solve it in three moves

  1. 1

    Classify the entity and engagement

    Use issuer, public-company, broker-dealer, private-company, and any stated statutory or contractual audit requirement before selecting standards.

    2026 Uniform CPA Examination Blueprints
  2. 2

    Select the governing authority

    Use PCAOB standards for covered reports and current AICPA SASs for nonissuer audits not otherwise required to use PCAOB standards.

    PCAOB Auditing Standards: Current standards and covered audit reports
  3. 3

    Rebuild the answer under that authority

    Apply the selected framework to evidence, communications, independence, report form, and any integrated-audit requirement.

    AICPA Statements on Auditing Standards: Current nonissuer scope and AU-C sections

Worked problem

Work the facts before choosing the answer

CPAPass illustration assumptions: Client A is an SEC issuer whose audit report is required to follow PCAOB standards. Client B is a private operating company whose financial-statement audit is not required by another rule or agreement to follow PCAOB standards.

CPAPass original exam illustration using stated assumptions

Show the work

Client A uses PCAOB auditing standards and applicable SEC requirements. Client B uses current AICPA Statements on Auditing Standards.

Rule source: PCAOB Auditing Standards: Current standards and covered audit reports

Answer

Solve each engagement under its governing framework and do not reuse one report template, independence conclusion, or standards citation for both.

Rule source: PCAOB Auditing Standards: Current standards and covered audit reports

Do it now

Test the same decision with a fresh question

Start with free AUD practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.

The trap and the repair

Common trap

Treating issuer and nonissuer as company-size labels misses that the classification selects the audit authority.

Repair

Write PCAOB or AICPA beside the stated entity and engagement facts before reading the answer choices.

Audit authority map

Entity facts select the standards before the report answer

Do not infer the authority from size or a casual use of “public.” Read the stated entity and audit requirement.

Engagement factPrimary authorityExam consequenceAuthority
Covered issuer or public-company audit reportPCAOB standards plus applicable SEC requirementsUse issuer procedures, communications, independence, and report formPCAOB Auditing Standards: Current standards and covered audit reports
Broker-dealer audit reportPCAOB standards within the stated regulatory scopeDo not force the engagement into a private-company size testPCAOB Auditing Standards: Current standards and covered audit reports
Nonissuer audit with no contrary requirementCurrent AICPA Statements on Auditing StandardsUse AU-C requirements and nonissuer report formAICPA Statements on Auditing Standards: Current nonissuer scope and AU-C sections
Blueprint questionExplicit issuer or nonissuer wording when requirements differUse the label before evaluating the answer choices2026 Uniform CPA Examination Blueprints

After a miss

Repair an issuer-versus-nonissuer miss

  1. 1

    Underline the entity and engagement requirement and write the governing standard setter beside it.

  2. 2

    Rework the illustration after adding a stated PCAOB requirement to the private-company audit and explain why size no longer decides.

  3. 3

    Answer a fresh AUD authority question and identify the framework before considering procedure or report wording.

Your exam workflow

  1. Step 1Read the requirementIdentify what the task asks you to decide about issuer vs nonissuer audit.
  2. Step 2Sort the factsUse issuer, public-company, broker-dealer, private-company, and any stated statutory or contractual audit requirement before selecting standards.
  3. Step 3Apply the ruleUse PCAOB standards for covered reports and current AICPA SASs for nonissuer audits not otherwise required to use PCAOB standards.
  4. Step 4Check the outputApply the selected framework to evidence, communications, independence, report form, and any integrated-audit requirement.

Quick questions

What is the shortest useful answer for issuer vs nonissuer audit?

PCAOB standards govern covered audit reports for public companies and other issuers and for broker-dealers. AICPA Statements on Auditing Standards govern nonissuer audits that are not otherwise required to follow PCAOB standards. The question's entity and engagement facts, not company size alone, select the authority.

How can issuer vs nonissuer audit appear on the CPA Exam?

AUD explicitly labels issuer and nonissuer questions when their requirements differ and can test authority, terminology, communications, procedures, independence, integrated-audit facts, and report form. The exact task can change, so identify the governing facts before applying the rule.

What is the most common mistake with issuer vs nonissuer audit?

Treating issuer and nonissuer as company-size labels misses that the classification selects the audit authority. Write PCAOB or AICPA beside the stated entity and engagement facts before reading the answer choices.

Where should I practice issuer vs nonissuer audit?

After the worked example, use AUD practice for a fresh question that requires the same decision. If the miss depends on framework-specific independence, review that handoff before trying another set.

How should I review issuer vs nonissuer audit after a missed question?

Underline the entity and engagement requirement and write the governing standard setter beside it. Rework the illustration after adding a stated PCAOB requirement to the private-company audit and explain why size no longer decides. Answer a fresh AUD authority question and identify the framework before considering procedure or report wording.

Sources behind the rule