Issuer vs. nonissuer audits: choose the governing standards
Use the entity and engagement facts to select PCAOB or AICPA standards before analyzing ICFR, communications, independence, or reporting.
The decision that earns the point
Identify the engagement facts and governing framework
PCAOB standards govern covered audit reports for public companies and other issuers and for broker-dealers. AICPA Statements on Auditing Standards govern nonissuer audits that are not otherwise required to follow PCAOB standards. The question's entity and engagement facts, not company size alone, select the authority.
Exam use
AUD explicitly labels issuer and nonissuer questions when their requirements differ and can test authority, terminology, communications, procedures, independence, integrated-audit facts, and report form.
Your scratch-paper plan
Solve it in three moves
- 1
Classify the entity and engagement
Use issuer, public-company, broker-dealer, private-company, and any stated statutory or contractual audit requirement before selecting standards.
2026 Uniform CPA Examination Blueprints - 2
Select the governing authority
Use PCAOB standards for covered reports and current AICPA SASs for nonissuer audits not otherwise required to use PCAOB standards.
PCAOB Auditing Standards: Current standards and covered audit reports - 3
Rebuild the answer under that authority
Apply the selected framework to evidence, communications, independence, report form, and any integrated-audit requirement.
AICPA Statements on Auditing Standards: Current nonissuer scope and AU-C sections
Worked problem
Work the facts before choosing the answer
CPAPass illustration assumptions: Client A is an SEC issuer whose audit report is required to follow PCAOB standards. Client B is a private operating company whose financial-statement audit is not required by another rule or agreement to follow PCAOB standards.
CPAPass original exam illustration using stated assumptions
Show the work
Client A uses PCAOB auditing standards and applicable SEC requirements. Client B uses current AICPA Statements on Auditing Standards.
Rule source: PCAOB Auditing Standards: Current standards and covered audit reportsAnswer
Solve each engagement under its governing framework and do not reuse one report template, independence conclusion, or standards citation for both.
Rule source: PCAOB Auditing Standards: Current standards and covered audit reportsDo it now
Test the same decision with a fresh question
Start with free AUD practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.
The trap and the repair
Common trap
Treating issuer and nonissuer as company-size labels misses that the classification selects the audit authority.
Repair
Write PCAOB or AICPA beside the stated entity and engagement facts before reading the answer choices.
Audit authority map
Entity facts select the standards before the report answer
Do not infer the authority from size or a casual use of “public.” Read the stated entity and audit requirement.
| Engagement fact | Primary authority | Exam consequence | Authority |
|---|---|---|---|
| Covered issuer or public-company audit report | PCAOB standards plus applicable SEC requirements | Use issuer procedures, communications, independence, and report form | PCAOB Auditing Standards: Current standards and covered audit reports |
| Broker-dealer audit report | PCAOB standards within the stated regulatory scope | Do not force the engagement into a private-company size test | PCAOB Auditing Standards: Current standards and covered audit reports |
| Nonissuer audit with no contrary requirement | Current AICPA Statements on Auditing Standards | Use AU-C requirements and nonissuer report form | AICPA Statements on Auditing Standards: Current nonissuer scope and AU-C sections |
| Blueprint question | Explicit issuer or nonissuer wording when requirements differ | Use the label before evaluating the answer choices | 2026 Uniform CPA Examination Blueprints |
After a miss
Repair an issuer-versus-nonissuer miss
- 1
Underline the entity and engagement requirement and write the governing standard setter beside it.
- 2
Rework the illustration after adding a stated PCAOB requirement to the private-company audit and explain why size no longer decides.
- 3
Answer a fresh AUD authority question and identify the framework before considering procedure or report wording.
Your exam workflow
- Step 1Read the requirementIdentify what the task asks you to decide about issuer vs nonissuer audit.
- Step 2Sort the factsUse issuer, public-company, broker-dealer, private-company, and any stated statutory or contractual audit requirement before selecting standards.
- Step 3Apply the ruleUse PCAOB standards for covered reports and current AICPA SASs for nonissuer audits not otherwise required to use PCAOB standards.
- Step 4Check the outputApply the selected framework to evidence, communications, independence, report form, and any integrated-audit requirement.
Keep the next step narrow
Quick questions
What is the shortest useful answer for issuer vs nonissuer audit?
PCAOB standards govern covered audit reports for public companies and other issuers and for broker-dealers. AICPA Statements on Auditing Standards govern nonissuer audits that are not otherwise required to follow PCAOB standards. The question's entity and engagement facts, not company size alone, select the authority.
How can issuer vs nonissuer audit appear on the CPA Exam?
AUD explicitly labels issuer and nonissuer questions when their requirements differ and can test authority, terminology, communications, procedures, independence, integrated-audit facts, and report form. The exact task can change, so identify the governing facts before applying the rule.
What is the most common mistake with issuer vs nonissuer audit?
Treating issuer and nonissuer as company-size labels misses that the classification selects the audit authority. Write PCAOB or AICPA beside the stated entity and engagement facts before reading the answer choices.
Where should I practice issuer vs nonissuer audit?
After the worked example, use AUD practice for a fresh question that requires the same decision. If the miss depends on framework-specific independence, review that handoff before trying another set.
How should I review issuer vs nonissuer audit after a missed question?
Underline the entity and engagement requirement and write the governing standard setter beside it. Rework the illustration after adding a stated PCAOB requirement to the private-company audit and explain why size no longer decides. Answer a fresh AUD authority question and identify the framework before considering procedure or report wording.