CPA Exam

CPA Auditing & Attestation: Evaluating design and implementation — Complete Study Guide

CPA Auditing & Attestation: Evaluating design and implementation — Complete Study Guide

You're feeling confident about internal controls, then bam—a simulation hits you. It describes a control, and your first instinct is to figure out if it's "working." That's the trap. Most candidates jump straight to testing operating effectiveness without first answering two foundational questions: Is this control even designed properly, and has it even been put in place? You can't test if a control is working if its blueprint is flawed or it only exists on paper.

For the CPA Auditing & Attestation (AUD) exam, evaluating the design and implementation of internal controls means assessing if a control is suitably designed to prevent or detect material misstatements (the blueprint) and confirming it actually exists and is in use (the construction). This is the mandatory first step before an auditor can even consider testing a control's operating effectiveness.

The CPA exam has a <50% pass rate.

VoraPrep's AI finds your weak spots before the exam does — adaptive practice that actually moves your score.

Try Free →

---

The Auditor's Three-Step Process for Internal Controls

The AICPA tests your judgment, not just your memory. For internal controls, that judgment follows a strict sequence. Getting this sequence wrong is a common reason candidates miss points on AUD simulations.

  1. Step 1: Evaluate Design and Implementation (D&I). This is your starting point for key controls. You ask: "Is the control designed to solve the problem?" and "Is it actually in place?" You do this through procedures like inquiry, observation, and inspecting documents (a walkthrough).
  2. Step 2: Assess Control Risk. Based on your D&I evaluation, you make an initial assessment. If a key control is poorly designed or not implemented, you must assess control risk as high. You can't rely on it. If it appears well-designed and is implemented, you may be able to assess control risk below high, but only if you complete the next step.
  3. Step 3: Test Operating Effectiveness. Only for controls that passed Step 1 and that you want to rely on do you proceed here. You test if the control operated consistently and effectively throughout the period. This involves re-performance, larger sample sizes, and more rigorous testing.

A well-designed control that isn't implemented is useless. A poorly designed control that is implemented perfectly is also useless. You must evaluate both D&I before you can draw any conclusions about control risk or plan your substantive tests. Ready to see if you can spot the difference? Try VoraPrep's free CPA practice questions and test your judgment.

---

Design vs. Implementation: A Practical Comparison

Confusing design and implementation is the most common trap on this topic. Think of it as reviewing a building's blueprint versus walking the construction site. The exam will test your ability to pinpoint which one is the problem.

AspectEvaluating DesignEvaluating Implementation
The Core Question"Is the control's blueprint logical? If it works as prescribed, will it prevent or detect a material misstatement?""Is the control actually built and in use? Does it exist beyond the policy manual?"
Auditor's FocusThe theory and structure of the control.The existence and application of the control at a point in time.
Common ProceduresInquiry of personnel, inspecting policy documents, reviewing system flowcharts.Observation of the control being performed, inquiry, inspecting a single transaction (as part of a walkthrough).
Example of a FlawA policy requires the controller to review invoices, but the controller also has the ability to add new vendors. This is a design flaw due to a lack of segregation of duties.A policy requires dual signatures on checks over $10k, but you observe managers regularly signing checks alone. This is an implementation failure.

---

Key Control Concepts Examiners Will Test

To apply your judgment, you need a firm grasp of the underlying rules. These aren't just definitions to memorize; they are tools for dissecting exam questions.

What is a Material Weakness in CPA AUD?

A material weakness is the most severe type of internal control deficiency. It's a deficiency, or a combination of them, where there's a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis.
  • The D&I Connection: A poorly designed control (e.g., no segregation of duties for cash handling) can be a material weakness if it opens the door to a reasonably possible material misstatement. However, a design flaw is not inherently a material weakness. Its severity depends on the potential financial impact. Likewise, a well-designed control that is consistently not implemented can also rise to the level of a material weakness.
  • Examiner's Trap: Don't automatically label every control issue a material weakness. You must consider both likelihood ("reasonable possibility") and magnitude ("material").

How Does the COSO Framework Relate to D&I?

The COSO framework's five components (Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities - "CRIME") provide the structure for an effective internal control system. When you evaluate a control's design, you are essentially assessing how a specific Control Activity fits within this broader framework to mitigate risks identified in the Risk Assessment process. Weakness in the Control Environment or Monitoring often leads to implementation failures.

What is an Engagement Quality Control Review (EQCR)?

An Engagement Quality Control Review (EQCR), sometimes informally called a "hot review," is a quality control procedure performed by the audit firm, not the client. It involves a review of the audit team's significant judgments and conclusions before the audit report is issued, especially for public company (issuer) audits.
  • Relevance to D&I: The EQCR reviewer would challenge the audit team's assessment of the client's control design and implementation. They ensure the team gathered sufficient evidence to support their conclusions about control risk and the resulting audit plan.

How Does Control Risk Assessment Drive the Audit?

Control risk is the risk that a client's internal controls will fail to prevent or detect a material misstatement. Your evaluation of D&I is the primary input for this assessment.
  • If D&I is poor: You assess control risk as high. You cannot rely on the controls. Your audit strategy shifts to performing more extensive, and expensive, substantive procedures (e.g., testing more transactions, using larger sample sizes).
  • If D&I is good: You may be able to assess control risk below high. But to justify that lower risk assessment, you must then test the operating effectiveness of those controls. If those tests pass, you can reduce the nature, timing, and extent of your substantive procedures. Evaluating D&I alone is never sufficient to assess control risk as low.

For a deeper dive into these core principles, our CPA Auditing and Attestation Cheat Sheet (2026) is an excellent resource.

---

Worked Example: From Scenario to Audit Plan

Let's apply the three-step process to a classic AUD simulation scenario.

Scenario:

You are auditing Cypress Manufacturing, a nonissuer. During your walkthrough of the purchasing process, you discover:

  • Policy: The company’s policy requires dual authorization by the Production Manager and the CFO for all raw material purchase orders (POs) over $5,000.
  • Observation: You select a sample of 10 POs over $5,000. Eight have only the Production Manager's signature. The other two have both signatures, but the CFO's is dated a week after the goods were received.
  • Inquiry: The CFO tells you, "I trust my managers. Getting my signature is more of a formality we catch up on later."
What is the deficiency, and how does it impact your audit plan?

Step-by-Step Walkthrough

Step 1: Evaluate Design and Implementation (D&I).
  • Design: Is the control's blueprint logical? Yes. Requiring dual authorization from both operations (Production Manager) and finance (CFO) for significant purchases is a well-designed control. It properly segregates duties and adds oversight.
  • Implementation: Is the control actually built and in use? No. In 100% of the cases sampled, the control was not applied as designed. A signature after the transaction is complete is not a preventative control; it's a rubber stamp. The control has not been implemented.
Step 2: Assess Control Risk.
  • Since a key preventative control over a significant transaction cycle (purchasing) is not implemented, you have no choice. You must assess control risk for the relevant assertions (e.g., occurrence of purchases, valuation of inventory) as high. You cannot rely on this control, so there's no point in proceeding to Step 3.
Step 3: Determine the Audit Response (No Testing of Operating Effectiveness).
  • Audit Plan: You will not test the operating effectiveness of this control. Instead, you must modify your audit plan to perform more extensive substantive procedures.
  • Specific Procedures: This could include testing a larger sample of vendor invoices, performing more detailed analytical procedures on raw material costs, and potentially increasing inventory price testing.
  • Communication: This is likely a material weakness given the CFO's dismissive attitude and the high deviation rate in a key cycle. You must communicate this in writing to management and those charged with governance.

The Tempting Wrong Answer and Why It's Wrong

Tempting Wrong Answer: "The auditor should test a larger sample of purchase orders to determine the operating effectiveness of the dual-authorization control." Why it's wrong: This answer incorrectly jumps to Step 3. Your D&I work (Step 1) already proved the control is not implemented. It's fundamentally broken. Testing its "operating effectiveness" is illogical and a waste of audit resources. The control has already failed, and your only path forward is to assess control risk at high and increase substantive testing. The exam loves to test this sequence.

---

Practice Questions: Test Yourself on D&I

Let's see if you can spot the key issue in these exam-style questions. VoraPrep's library of over 9,500 adaptive questions includes hundreds of scenarios like these.

Sample Q1: An auditor is performing a walkthrough for the cash disbursements cycle. The auditor notes that the company's policy requires a supervisor to approve all invoices before payment, a control that appears suitably designed. However, the auditor observes that the accounts payable clerk, who also prints the checks, approves the invoices herself. This issue represents:

A. A control design deficiency.
B. A control implementation deficiency.
C. A deficiency that should be ignored if immaterial.
D. A control that requires further testing of operating effectiveness.
Explanation: The correct answer is B. A control implementation deficiency.
  • Why B is correct: The policy itself (supervisor approval) is "suitably designed." The problem is that this policy is not being followed in practice. The clerk is bypassing the designed control, which is a failure of implementation.
  • Why A is incorrect: The design (the rule in the book) is sound. The execution is the problem.
  • Why D is incorrect: Just like in our worked example, there is no reason to test the operating effectiveness of a control that you've already observed is not being implemented.

Sample Q2: During the planning phase of an audit for an issuer, the auditor identifies a newly implemented automated control designed to match purchase orders, receiving reports, and vendor invoices. The control is complex but appears logically sound. What is the auditor's most appropriate next step regarding this control?

A. Assess control risk as low because the control is automated.
B. Conclude that the control is a material weakness due to its complexity.
C. Perform a walkthrough to confirm the control has been placed in operation.
D. Select a large sample of transactions to test the control's operating effectiveness.
Explanation: The correct answer is C. Perform a walkthrough to confirm the control has been placed in operation.
  • Why C is correct: The auditor has evaluated the design ("appears logically sound"). According to the three-step process, the next step is to evaluate implementation—confirming it has been "placed in operation." A walkthrough, which traces a transaction from start to finish, is the perfect procedure for this.
  • Why A and D are incorrect: Both of these answers skip a step. You cannot assess control risk as low (A) or test operating effectiveness (D) until you have first confirmed the control is actually implemented.

---

Frequently asked questions

How many questions on D&I appear on the CPA exam?

Concepts of internal control design and implementation are foundational to the Risk Assessment area of the AUD blueprint, which makes up 25-35% of your exam score. You will see these principles tested in numerous multiple-choice questions and are very likely to see them appear in at least one task-based simulation.

What's the best way to study for this topic?

Focus on the sequence: Design -> Implementation -> Operating Effectiveness. Use practice questions to train your brain to ask, "Is the blueprint flawed?" before you ask, "Is it working?" VoraPrep's AI tutor, Vory, can walk you through scenarios 24/7, helping you solidify this critical thinking process.

Is D&I tested in simulations or only multiple choice?

It is heavily tested in both. MCQs will test your knowledge of the definitions and the proper sequence of audit steps. Task-Based Simulations will give you exhibits like flowcharts or interview notes and require you to identify design flaws or implementation failures and describe the impact on the audit plan.

How does SOX 404 affect the evaluation of D&I?

For public companies (issuers), SOX Section 404 requires management to report on the effectiveness of internal control over financial reporting (ICFR), and the auditor must issue a separate opinion on ICFR. This elevates the importance of evaluating D&I, as any identified material weaknesses must be reported in the auditor's report on ICFR.

---

Related Resources

Official resources and references

---

Ready to Pass Your CPA Exam? Stop memorizing and start thinking like an examiner. VoraPrep's adaptive learning engine, 9,500+ practice questions, and 24/7 AI tutor are designed to build your professional judgment. We'll find your weak spots and give you the targeted practice you need to walk into the exam with confidence. Visit voraprep.com to get started. Start Your Free 7-Day Trial at voraprep.com →

Studying for the CPA?

Stop guessing which topics to review. VoraPrep's adaptive engine diagnoses exactly where you're losing points and rebuilds those areas. 10 minutes a day, measurable score improvement.

Start your free trial → voraprep.com

Don't let this be why you retake the CPA.

Most candidates fail because they study the wrong things, not because they don't study enough. VoraPrep's AI identifies your actual weak spots and targets them — so you walk in knowing exactly where you're strong.

Start Free — No Credit Card →

Keep reading