Applying the auditing standards hierarchy is like being a judge interpreting legal precedent. You don’t just memorize a list of laws; you learn which one governs the case in front of you—a public company, a private business, or a government agency. Getting this judgment call wrong on the CPA exam is a fast path to a failing score, not because you didn't know the rules, but because you applied the wrong rulebook.
The Auditing Standards Hierarchy is the framework CPAs use to determine which set of professional standards (PCAOB, AICPA, or GAO) applies to a specific engagement. It prioritizes standards based on the entity type being audited—issuer (public), non-issuer (private), or government. Mastering this decision process is critical for passing the AUD section of the CPA exam.
The AUD Exam at a Glance: Core Requirements
- Passing score: 75 on a 0-99 scale
- Exam sections: Auditing and Attestation (AUD), Financial Accounting and Reporting (FAR), Regulation (REG), and one Discipline (BAR, ISC, or TCP)
- Official body: American Institute of Certified Public Accountants (AICPA)
- Exam format: 4 hours per section with multiple-choice questions (MCQs) and task-based simulations (TBS)
- Governing standards: Statements on Auditing Standards (SAS), PCAOB Auditing Standards (AS), Government Auditing Standards (GAS)
- Pass rate context: The AICPA reported the cumulative pass rate for the AUD section was 47.16% in 2023 (AICPA), underscoring its difficulty.
Core Principles for Applying the Auditing Hierarchy
- The hierarchy is a decision tree, not a list; your first question must always be, "What type of entity am I auditing?"
- For issuers (public companies), PCAOB standards are mandatory, incorporating some AICPA standards as an interim base and adding their own rules.
- Government Auditing Standards (the "Yellow Book") add specific requirements on top of GAAS, including stricter CPE and reporting rules.
- The exam tests your ability to select the most authoritative standard for a given scenario, a classic judgment-based question.
- A firm's internal quality management system, governed by AICPA SQMS, provides the foundation for applying all other auditing standards correctly.
- Misapplying the Yellow Book's specific CPE requirements, particularly the subject matter rules, is a common trap that invalidates an otherwise correct answer.
What is the Auditing Standards Hierarchy and Why It Matters for the CPA Exam
The auditing standards hierarchy is the authoritative framework that dictates which rules an auditor must follow for a specific engagement. Think of it as a roadmap for navigating the different sets of professional standards. You wouldn't use a map of New York to navigate Los Angeles; similarly, you don't apply private company auditing standards to a public company regulated by the SEC.
On the AUD exam, this concept is woven into dozens of questions. The examiners won't ask you to simply list the standards. Instead, they will present a scenario and expect you to diagnose the entity type and apply the correct set of rules. This is a test of application, not just recall. Try VoraPrep's free CPA practice questions to see how these scenarios are structured.
Studying for CPA AUD? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
The most common mistake candidates make is over-simplifying. They might memorize that "PCAOB is for public companies" but miss the crucial relationship between PCAOB standards and GAAS. Or they might see a non-profit client and assume GAAS applies, forgetting to check if it receives significant federal funding that would trigger Yellow Book requirements. The exam loves these gray areas because they separate candidates who memorized from those who can reason.
The Four Pillars of Auditing Authority
The core components you must master are the different standard-setting bodies and the firm-level systems that ensure compliance. The hierarchy isn't just about individual engagements; it begins with the firm's own policies and procedures.
AICPA (GAAS) for Non-issuers
Generally Accepted Auditing Standards (GAAS), issued by the AICPA through Statements on Auditing Standards (SAS), are the foundation for audits of private companies, non-profits, and other non-issuers in the United States. These standards are codified in the "AU-C" sections and represent the baseline requirements for performance, reporting, and ethics in non-issuer audits.PCAOB for Issuers
The Public Company Accounting Oversight Board (PCAOB) was established by the Sarbanes-Oxley Act of 2002. Its Auditing Standards (AS) are mandatory for audits of "issuers"—public companies registered with the SEC.Here is a critical nuance the exam will test: the PCAOB did not start from scratch. In 2003, it adopted the AICPA's existing Statements on Auditing Standards as its interim auditing standards. These interim standards (codified as AU) remain in effect unless specifically amended or superseded by a new PCAOB Auditing Standard (AS). So, PCAOB standards incorporate GAAS as a base and then build upon it with their own, often more stringent, rules. They do not simply replace GAAS entirely.
GAO (Yellow Book) for Government Entities
The U.S. Government Accountability Office (GAO) issues Government Auditing Standards, commonly known as the "Yellow Book." These standards apply to audits of government organizations, programs, activities, and entities that receive government awards. The key thing to remember is that the Yellow Book builds on top of GAAS. It incorporates AICPA standards by reference and then adds more requirements, particularly regarding ethics, independence, and continuing professional education (CPE).A critical Yellow Book rule tested on the exam involves CPE. Auditors performing work under GAGAS must complete 80 hours of CPE every two years.
- At least 24 hours must be directly related to the government environment, government auditing, or the specific environment of the audited entity.
- At least 20 hours must be completed in any one year of the two-year period.
The common trap is believing the 20 hours must be completed in each year. That is incorrect. The rule provides flexibility, but the 24-hour subject matter requirement is rigid.
Firm-Level Quality Management (SQMS)
A firm’s system of quality management is the bedrock upon which all audits are built. The AICPA's Statements on Quality Management Standards (SQMS), particularly SQMS No. 1, require firms to design, implement, and operate a system to manage the quality of their engagements. This system includes processes for accepting clients, assigning personnel, and monitoring compliance with professional standards—including selecting the right standards from the hierarchy.Here is a quick reference table to keep the main standards straight:
| Standard | Governing Body | Applies To | Key Distinctions |
|---|---|---|---|
| GAAS | AICPA | Non-issuers (private companies, non-profits) | The baseline for U.S. non-issuer audits. Codified as AU-C. |
| PCAOB AS | PCAOB | Issuers (publicly-traded companies) | Mandatory for SEC registrants. Incorporates GAAS as interim standards and adds its own rules, including for ICFR audits. |
| GAS / Yellow Book | GAO | Government entities and recipients of federal funds | Builds upon GAAS. Adds specific CPE, independence, and reporting requirements. |
Worked Example with Step-by-Step Solution
Examiners test your judgment by creating scenarios that require you to navigate this hierarchy under pressure. Let's walk through a realistic example.
Scenario: Trident CPAs, a mid-sized accounting firm, has three new clients for the 2026 year-end audit:- Innovate Corp: A publicly-traded tech company listed on the NASDAQ.
- Builders LLC: A large, privately-held construction company with no public debt.
- City of Oakhaven: A municipal government that receives federal grants for infrastructure projects.
The partner assigned to the City of Oakhaven audit, David, completed 30 hours of CPE this year, all focused on advanced corporate tax strategies. Which of the following is true regarding the standards applicable to these engagements?
A) Innovate Corp requires a GAAS audit; Builders LLC and the City of Oakhaven require PCAOB audits. B) All three engagements must be conducted in accordance with PCAOB Auditing Standards. C) Innovate Corp requires a PCAOB audit, Builders LLC requires a GAAS audit, and the firm may have a quality management issue with the City of Oakhaven engagement. D) The City of Oakhaven audit must be conducted under GAAS, and the partner’s CPE is sufficient.
Step 1: Identify the Entity Type for Each Client
This is your first move. Don't think about standards yet, just classify the clients.
- Innovate Corp: "Publicly-traded... on the NASDAQ." This makes it an issuer.
- Builders LLC: "Privately-held." This makes it a non-issuer.
- City of Oakhaven: "Municipal government that receives federal grants." This makes it a government entity.
Step 2: Apply the Correct Standard-Setting Body
Now, match the entity type to the governing body.
- Issuer (Innovate Corp): The audit must follow PCAOB Auditing Standards.
- Non-issuer (Builders LLC): The audit must follow the AICPA's Generally Accepted Auditing Standards (GAAS).
- Government Entity (City of Oakhaven): The audit falls under Government Auditing Standards (GAS/Yellow Book).
Step 3: Analyze the Nuances and Potential Traps
This is where the exam separates a 74 from a 75. Look at the specific facts provided.
- The partner, David, is assigned to the City of Oakhaven audit. This audit requires compliance with the Yellow Book.
- The Yellow Book has a specific CPE requirement: at least 24 of the 80 hours every two years must be in government-related subjects.
- David's 30 hours were all in corporate tax. He has zero hours that qualify under the government subject matter rule.
- Therefore, David is not qualified under Yellow Book standards to lead this audit. This is a failure in the firm's quality management system related to engagement performance and personnel assignment.
The Tempting Wrong Answer: (D)
Answer (D) is tempting because it correctly identifies that a government audit uses GAAS as a base. A candidate in a hurry might see "GAAS" and "government" and select it, ignoring the crucial detail about the partner's CPE. They forget that the Yellow Book adds to GAAS with more stringent rules. This distractor preys on incomplete knowledge.
The Correct Answer and Rationale: (C)
Answer (C) correctly identifies all three situations:
Check Your State’s Exact CPA Exam Requirements
Every state has different credit hour, ethics, and residency rules. Use our 55-jurisdiction checker to verify your eligibility before applying.
- Innovate Corp (issuer) -> PCAOB audit.
- Builders LLC (non-issuer) -> GAAS audit.
- City of Oakhaven -> The firm has a problem. Assigning an unqualified partner violates the performance principle under both GAAS and the specific requirements of the Yellow Book, indicating a failure in their system of quality management.
This question didn't just test if you could match "public" to "PCAOB." It tested if you understood the entire ecosystem: the hierarchy, the specific rules within each standard (CPE), and how it all connects back to the firm's overall responsibility for quality. This is how VoraPrep's adaptive learning engine helps you practice—by targeting these multi-step reasoning problems. For a deeper dive, review our guide on how to evaluate audit design and implementation.
Practice Questions: Test Yourself on Auditing Standards Hierarchy
The VoraPrep question bank has over 9,500 questions, including many scenarios covering the auditing standards hierarchy. Here are three examples to test your understanding.
Sample Question 1: Apex Auditors, a CPA firm, is evaluating a potential new engagement to audit the financial statements of a publicly-traded company. Which of the following sets of standards would Apex be required to follow if they accept the engagement?A) Public Company Accounting Oversight Board (PCAOB) Auditing Standards. B) Statements on Standards for Attestation Engagements (SSAEs). C) Generally Accepted Auditing Standards (GAAS). D) Statements on Standards for Accounting and Review Services (SSARS).
Answer: A. Audits of publicly-traded companies (issuers) are governed by the PCAOB. GAAS (C) applies to non-issuers. SSAEs (B) and SSARS (D) apply to attestation and review/compilation engagements, respectively, not financial statement audits of issuers. Sample Question 2: A CPA firm is designing its system of quality management to comply with AICPA Statement on Quality Management Standards (SQMS). A key component of this system is the process for accepting and continuing client relationships. This process primarily helps the firm to address which of the following risks?A) The risk of issuing an incorrect audit opinion due to financial statement misstatements. B) The risk of employee turnover and a lack of qualified staff. C) The risk of being associated with a client whose management lacks integrity. D) The risk of violating PCAOB inspection requirements.
Answer: C. The client acceptance and continuance component of a quality management system is specifically designed to evaluate the integrity and ethics of a potential client's management. While other risks are relevant to the firm, this component directly addresses the risk of association with a problematic client. This links to the firm's ethical requirements, a topic also covered in our guide to required communications in an audit. Sample Question 3: Maria, a CPA at Apex Auditors, is assigned to lead an audit engagement for a local municipal government. This engagement is subject to Government Auditing Standards (the "Yellow Book"). Which of the following is an additional requirement imposed by the Yellow Book that is not found in GAAS for a typical non-issuer audit?A) A requirement for auditors to complete specific continuing professional education (CPE) related to government auditing. B) A requirement to obtain an understanding of internal control. C) A requirement to obtain a management representation letter. D) A requirement to be independent in mind and appearance.
Answer: A. While GAAS requires CPE, the Yellow Book imposes more stringent and specific requirements, including a set number of hours in government-related topics. Understanding internal control (B), obtaining a management representation letter (C), and being independent (D) are all fundamental requirements under GAAS as well. The specific CPE is the key differentiator.To drill more questions like these and let our adaptive algorithm find your weak spots, explore VoraPrep's full breakdown of the CPA exam format.
Study Tips and Exam-Day Strategy
Your first priority should be to create a decision tree, not a list of facts. On a whiteboard or in a notebook, start with the question: "What type of entity is it?" From there, branch out to Issuer, Non-issuer, and Government Entity, and list the corresponding standards and key requirements under each. This visual map reinforces the judgment process.
On exam day, when you encounter a question about standards, your first mental step is to scan the prompt for keywords like "publicly-traded," "SEC registrant," "private," or "city/county/federal funds." This immediately tells you which branch of the decision tree to follow. Don't let yourself get bogged down in the details of the scenario until you've established the governing framework.
In your final week of review, focus on mixed practice sets. Intentionally do MCQs from different topics back-to-back to simulate the real exam's random question order. Pay special attention to questions that combine the hierarchy with ethics or quality control. This topic doesn't live in a vacuum; it's the foundation for nearly every other AUD concept.