AUD vs ISC CPA Exam: Controls, Evidence, and Study Order
AUD is a required Core section about audit and attestation work. ISC is an optional Discipline about systems, data, security, privacy, and SOC engagements. Controls connect the work, but the Blueprints test different objectives.
Quick answer
AUD approaches controls through risk assessment, procedures, evidence, conclusions, and reporting. ISC tests the information-system environment and SOC engagement considerations more directly. The same workplace can appear in both, but the candidate task changes.
Compare with your own results
Practice AUD and ISC in one free account
Keep explanations and progress together, or sample either public question set before registering.
Core
AUD
Discipline
ISC
Conditional
Study order
Official 2026 Blueprint areas
These area names and weight ranges come from the current AICPA Blueprint. The comparison and study guidance below are CPAPass interpretation, not AICPA sequencing rules.
AUD: Auditing and Attestation
Source-derived- Area I: Ethics, Professional Responsibilities and General Principles15-25%
- Area II: Assessing Risk and Developing a Planned Response25-35%
- Area III: Performing Further Procedures and Obtaining Evidence30-40%
- Area IV: Forming Conclusions and Reporting10-20%
ISC: Information Systems and Controls
Source-derived- Area I: Information Systems and Data Management35-45%
- Area II: Security, Confidentiality and Privacy35-45%
- Area III: Considerations for System and Organization Controls (SOC) Engagements15-25%
Blueprint tasks are representative, not exhaustive. The number of listed tasks does not establish content weight or predict the exact questions a candidate will receive.
Official-source contract reviewed 2026-08-03
How AUD and ISC connect or separate
The labels below distinguish a genuinely shared subject from adjacent real-world context and clearly separate scope. They do not estimate an overlap percentage.
| Comparison | In AUD | In ISC | Study implication |
|---|---|---|---|
Risk and control context Adjacent context | Assessing Risk and Developing a Planned Response uses an understanding of the entity and controls to plan audit work. | Information Systems and Data Management plus Security, Confidentiality and Privacy examine technology environments and risks. | AUD asks what the risk means for the engagement; ISC asks for more precise systems and controls reasoning. |
Evidence and SOC context Adjacent context | Procedures, evidence, conclusions, and reporting determine how engagement work supports an auditor conclusion. | Considerations for System and Organization Controls Engagements focuses explicitly on SOC engagements. | Do not memorize one report label without identifying the engagement, user, evidence, and conclusion involved. |
Professional responsibilities Distinct scope | Ethics, Professional Responsibilities and General Principles is an explicit AUD content area. | ISC does not list that as a separate content area. | ISC familiarity does not replace AUD ethics and engagement-principle preparation. |
Worked comparison
A service organization processes transactions for a user entity and a report describes controls at the service organization.
AUD question
AUD-style work may ask how the information affects risk assessment, evidence, procedures, or the audit conclusion.
ISC question
ISC-style work may ask about the system, controls, criteria, or engagement considerations behind the report.
Practice cue: Name the perspective before answering: financial-statement auditor, system or control owner, or SOC engagement practitioner.
CPAPass guidance: use your background to choose the order
AUD-first can help candidates who need an engagement and evidence framework. ISC-first can help candidates whose systems and control knowledge is already strong. Neither is an official prerequisite.
Consider AUD first when
- Audit risk, evidence, and reporting language are less familiar than technology terms.
- You want an engagement context before studying SOC and systems details.
Consider ISC first when
- You have chosen ISC and work with systems, IT controls, cybersecurity, or SOC engagements.
- A diagnostic shows the technology vocabulary is your strongest entry point.
Exception: Do not assume that a technology job makes AUD reporting questions automatic, or that audit experience makes ISC security terminology automatic.
Common mistakes to avoid
- 1Treating the auditor perspective and the systems perspective as interchangeable.
- 2Assuming all SOC-related questions test the same objective in both sections.
- 3Skipping AUD ethics and reporting because ISC controls felt familiar.
- 4Choosing ISC from its format alone instead of testing the actual content.
One control, different candidate tasks
A control can matter to both an audit and an information-systems environment. In AUD, the candidate asks how the control affects risk, planned work, evidence, and conclusions. In ISC, the candidate needs more specific command of systems, data, security, privacy, and SOC concepts.
This perspective check prevents a common error: selecting an answer that describes a plausible control but does not answer the role or engagement in the question.
How to practice the connection
Take one control scenario and write two headings: AUD consequence and ISC consequence. Under AUD, identify the risk, procedure, evidence, or reporting effect. Under ISC, identify the control objective, systems risk, security principle, or SOC consideration.
If you can explain only one side, use the matching free-practice route. Do not repeat the comfortable section and call the pair covered.
Compare AUD and ISC with real questions
Use the guides to understand scope, then practice and download samples for both sections. If one is a Discipline, use the Discipline guide before locking the choice.
AUD section guide
Review current format, scope, examples, and study troubleshooting.
ISC section guide
Review current format, scope, examples, and study troubleshooting.
Free AUD practice
Use questions to test whether the scope feels familiar in practice.
Free ISC practice
Use questions to test whether the scope feels familiar in practice.
Free AUD PDF sample
Download the section sample and review the teaching explanations.
Free ISC PDF sample
Download the section sample and review the teaching explanations.
Find whether AUD or ISC needs your next drill
Create a free CPAPass account to practice both sections, review why you missed each question, and direct the next set toward the weaker pattern.
Start free AUD and ISC practiceFrequently Asked Questions
- Should I take AUD or ISC first?
- Either can be reasonable. CPAPass suggests AUD first for candidates who need engagement context and ISC first for candidates with strong systems experience. The AICPA does not require an order.
- How are controls tested differently in AUD and ISC?
- AUD connects controls to risk, procedures, evidence, conclusions, and reporting. ISC focuses more directly on systems, data, security, privacy, and SOC engagement considerations.
- How much do AUD and ISC overlap?
- No official overlap percentage is published. The Blueprint areas show adjacent control and engagement contexts, not one duplicated syllabus.