CPA Exam · 20 min read Updated

CPA AUD Deep Dive: Group Audits Made Practical (2026)

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CPA AUD Deep Dive: Group Audits Made Practical (2026)

Key Takeaways

  • GEP Responsibility: The Group Engagement Partner (GEP) holds 100% ultimate responsibility for the group audit opinion on consolidated financial statements.
  • Delegation: GEP responsibility cannot be delegated or shared, even when component auditors perform significant work.
  • Referencing Component Auditors: The GEP generally does not reference component auditors in the audit report, as it implies a prohibited division of responsibility.
  • Exception to Referencing: Referencing component auditors is only permissible if explicitly required by law or regulation, a rare occurrence on the CPA exam.
  • Governing Standard: SAS No. 149 (AU-C Section 600) governs group audits, emphasizing the GEP's overarching responsibility.

The biggest trap in group audits isn’t memorizing the rules for component materiality. It’s misunderstanding the one principle that governs every decision: the Group Engagement Partner (GEP) is on the hook for everything, always. Get that wrong, and you’ll misinterpret every scenario the AUD exam throws at you, turning straightforward questions into point-killers.

Quick answer

In a CPA AUD group audit, the Group Engagement Partner (GEP) is solely responsible for the audit opinion on the consolidated financial statements. The GEP must direct and supervise the audit, evaluate the competence of component auditors, but cannot delegate their ultimate responsibility or reference component auditors in the report except in rare, legally required circumstances.

Key facts

  • GEP Responsibility: The Group Engagement Partner (GEP) holds 100% ultimate responsibility for the group audit opinion on consolidated financial statements.
  • Delegation: GEP responsibility cannot be delegated or shared, even when component auditors perform significant work.
  • Referencing Component Auditors: The GEP generally does not reference component auditors in the audit report, as it implies a prohibited division of responsibility.
  • Exception to Referencing: Referencing component auditors is only permissible if explicitly required by law or regulation, a rare occurrence on the CPA exam.
  • Governing Standard: SAS No. 149 (AU-C Section 600) governs group audits, emphasizing the GEP's overarching responsibility.

Key Takeaways for Group Audits (2026)

  • Ultimate Responsibility is Non-Negotiable: The Group Engagement Partner (GEP) is always 100% responsible for the group audit opinion. This responsibility cannot be shared or delegated, regardless of who audits the components.
  • Referencing is Prohibited (Almost Always): The default answer on the CPA exam is that the GEP does not reference the component auditor in the audit report. Doing so implies a division of responsibility, which is forbidden unless required by law or regulation. This is a classic exam trap.
  • Materiality is Layered: The GEP sets materiality for the group as a whole. Component performance materiality is then set lower for individual components to reduce the risk that small, individual misstatements aggregate into a material misstatement for the group.
  • Significance Drives Work Effort: The GEP must identify "significant components" based on financial size or specific risks. The audit work required for a significant component is substantially more involved than for other components.
  • SAS No. 149 is Here: For 2026 exams, the new SAS No. 149 standard refines the group audit approach, emphasizing a more robust, risk-based methodology and enhancing documentation requirements. It moves away from rigid rules to a more scalable model based on assessed risk.

What Makes Group Audit Questions So Difficult on the CPA Exam?

Group audit questions on the AUD exam are designed to test your professional judgment, not just your ability to recall a rule. Candidates consistently get tangled in the same few areas because the scenarios require you to apply core principles under pressure.

  1. Responsibility Webs: The exam will present scenarios with multiple auditors and complex corporate structures. The trap is to get lost in who did what. The correct approach is to always anchor your analysis to the GEP's ultimate accountability. If a question asks what the GEP should do, the answer will always reflect their non-delegable duty to obtain sufficient, appropriate evidence for the group opinion.
  2. Materiality Puzzles: You'll be given group materiality, group performance materiality, and component performance materiality. A classic simulation might give you a small, uncorrected misstatement from a component auditor. The trap is to dismiss it because it's below group materiality. The correct thinking is to aggregate all uncorrected misstatements and compare the total to group performance materiality while also considering the qualitative aspects.
  3. Reporting Traps: The question of when to reference a component auditor is the most common distractor. Candidates who haven't mastered the core responsibility principle often choose this tempting but incorrect option because it "seems fair" to mention the other auditor. The AICPA knows this and uses it to separate passing candidates from failing ones.

To ground yourself, use this mental model: The Group Engagement Partner is the captain of the ship. They are accountable for the entire voyage (the group audit opinion), even if different crew members (component auditors) are responsible for specific sections of the ship (the components). The captain signs the logbook and takes full responsibility for reaching the destination safely. Once you internalize this, the rules fall into place.

Free 5-Min Diagnostic

Studying for CPA AUD? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

Who's Who in a Group Audit?

The CPA exam uses precise terminology. Confusing these roles is an easy way to lose points on multiple-choice questions and simulations.

RolePrimary ResponsibilityKey Relationship & Exam Nuance
Group Engagement Partner (GEP)Solely responsible for directing, supervising, performing, and reporting on the group audit. Signs the group audit report.The "captain of the ship." Every question about the final opinion, risk assessment, or overall strategy ultimately comes back to the GEP's judgment and responsibility.
Group Engagement TeamAssists the GEP in planning and performing the group audit. Includes partners and staff from the GEP's firm.The GEP's own crew. They perform work at the group level (e.g., auditing the consolidation process) and may also act as component auditors for some subsidiaries.
Component AuditorAn auditor who, at the request of the group engagement team, performs work on the financial information of a component for the group audit.An external specialist or another office of the GEP's firm engaged for a specific task. The GEP must evaluate their competence and independence but can never delegate final responsibility to them.

How Do You Know if Group Audit Standards Even Apply?

Group audit standards (AU-C 600, and now SAS No. 149 for 2026 exams) apply whenever you're auditing group financial statements. This is a broader definition than many candidates realize.

Group financial statements include the financial information of more than one component. This can include:

  • Consolidated Financial Statements: The classic parent company and its subsidiaries. This is the most common scenario on the exam.
  • Combined Financial Statements: Financials for a group of entities under common control (e.g., several companies owned by the same individual).
  • Single Entity with Multiple Locations/Divisions: This is a subtle trap. A single legal entity can be a "group" if its separate divisions or branches are audited by different audit teams. For example, a national bank might have its East Coast operations audited by the New York office and its West Coast operations audited by the Los Angeles office. The partner signing the overall opinion is the GEP.
  • Equity Method Investments: The standards can apply when an equity method investee's financial information is significant to the group and needs to be audited as part of the group audit. The GEP must determine if the investee constitutes a "component" for this purpose, based on its significance and the risks it presents to the investor entity's financials.

The trigger is simple: are you, as the GEP, opining on financial statements that include financial information from a component you are not auditing entirely by yourself? If yes, group audit standards apply.

A Step-by-Step Framework for Thinking Through Group Audits

Forget memorizing disconnected rules. The AICPA wants to see if you can think systematically. Use this logical framework to dissect any group audit question the exam throws at you.

Step 1: Acceptance and Continuance – Can We Ethically Take This Job?

Before any work begins, the GEP must perform critical due diligence. The core question is: Can I obtain sufficient appropriate audit evidence to form the group audit opinion?

This involves asking:

  • Access: Will my team have unrestricted access to component auditors, their work papers, component management, and those charged with governance? If management imposes a scope limitation here, it's a major red flag.
  • Competence & Independence: Is the component auditor competent and independent? This isn't a rubber stamp. The GEP must actively evaluate their professional qualifications, their understanding of the relevant reporting framework (e.g., U.S. GAAP), and their independence. If the component auditor is not independent, the GEP cannot use their work.
  • GEP's Own Competence: Does the group engagement team have the specialized skills, knowledge, and time to manage a complex, multi-location audit?

If the answer to any of these is a hard "no," the GEP likely cannot accept or continue the engagement. The exam might test this with a scenario where a foreign component's government restricts access to information. In that case, the GEP may have to disclaim an opinion.

Step 2: Planning and Materiality – Setting the Strategic Blueprint

This is the blueprint phase and a hotbed for exam questions.

  • Identify Components: List every subsidiary, division, or entity included in the group financials.
  • Assess Significance: Determine which components are "significant." A component is significant if it's either individually financially significant to the group or likely to include significant risks of material misstatement for the group (e.g., a small but complex derivative-trading subsidiary in a conservative manufacturing group).
  • Set Materiality (The Layer Cake): This is crucial. The GEP establishes a hierarchy of materiality:
  1. Group Materiality: The materiality for the financial statements as a whole.
  2. Group Performance Materiality: Set lower than group materiality to reduce the probability that the aggregate of uncorrected and undetected misstatements exceeds group materiality. This is the key benchmark for evaluating identified misstatements during the audit.
  3. Component Materiality: Set for an individual component. It will always be lower than group materiality.
  4. Component Performance Materiality: Set lower than component materiality. This is what the component auditor uses to guide their work.

This structure creates a safety buffer. An error that is immaterial to the group might be material to a component, ensuring it gets identified and reported to the GEP.

Step 3: Risk Assessment and Work Effort – Deciding Who Does What

Based on the significance of each component, the GEP designs the audit approach. This is where the risk-based model of SAS No. 149 really shines.

  • For Significant Components: The GEP must be deeply involved. The standards require more than just taking the component auditor's report at face value. The GEP's involvement might include:
  1. Having the group engagement team audit the component directly.
  2. Having a component auditor perform a full audit, but the GEP participates in their risk assessment, reviews their workpapers, and evaluates the evidence they obtained.
  3. Having a component auditor perform a full audit of the component, while the GEP performs specified audit procedures on high-risk areas (e.g., revenue recognition or inventory valuation) of that component.
  • For Non-Significant Components: The GEP has more flexibility. The primary work effort will be analytical procedures at the group level to identify any unusual trends or relationships. If those procedures flag potential risks, the GEP may decide to perform or request additional audit procedures on those components, but a full audit is not automatically required.

Step 4: Communication – Keeping Everyone on the Same Page

Clear, two-way communication is mandated by auditing standards and is essential for a successful group audit.

  • GEP to Component Auditor (The To-Do List): The GEP must communicate their requirements clearly. This isn't a casual phone call; it's a formal part of the audit file.
  • The specific work to be performed and the expected form and content of their communication.
  • Ethical requirements, especially independence.
  • Group and component performance materiality levels.
  • Identified significant risks of material misstatement relevant to the component's audit.
  • Component Auditor to GEP (The Findings): The component auditor must communicate back in a timely manner.
  • Confirmation of their compliance with independence requirements.
  • Any identified significant risks at the component level.
  • All misstatements found during the audit (corrected and uncorrected).
  • Their overall findings and the audit report they issued.

This dialogue is crucial for the GEP to effectively supervise the audit. If you're reviewing this area, our CPA Auditing & Attestation: Required communications — Complete Study Guide provides a detailed breakdown of these critical interactions.

Step 5: Evaluating Evidence – Can I Trust This Work?

The GEP's professional judgment is paramount. They cannot simply accept the component auditor's report without scrutiny. The GEP must:

  • Discuss significant findings and risks with the component auditor and component management.
  • Review the component auditor's audit documentation for significant components to understand the work performed and the conclusions reached.
  • Determine if the work performed by the component auditor is sufficient and appropriate to support the group audit opinion.

If the GEP concludes the work is deficient or the evidence is insufficient, they must take action. This could involve performing additional procedures themselves, requesting the component auditor to perform more work, or, in serious cases, concluding that a modification to the group audit opinion is necessary.

✨ Free Interactive Tool

Check Your State’s Exact CPA Exam Requirements

Every state has different credit hour, ethics, and residency rules. Use our 55-jurisdiction checker to verify your eligibility before applying.

Check State Requirements →

Step 6: Auditing the Consolidation – Is the Puzzle Assembled Correctly?

The component audits are just one piece. The GEP has a specific responsibility to audit the consolidation process itself. This is a group-level procedure performed by the group engagement team.

  • Verify Consolidation Adjustments: Testing the accuracy and completeness of adjustments like intercompany profit eliminations, goodwill calculation and impairment, and fair value adjustments from acquisitions.
  • Check Inclusion: Ensuring the financial information from components has been properly included and translated (if necessary) in the group financial statements.
  • Evaluate Disclosures: Assessing whether disclosures related to the group structure, subsidiaries, and any restrictions on assets are appropriate under the applicable financial reporting framework.

Step 7: Reporting – Issuing the Final Opinion

This is the finish line and the source of the #1 exam trap.

  • The GEP forms an opinion on the group financial statements as a whole.
  • The Big Rule: The GEP issues the report in their own name and does not reference the component auditor. Referencing the component auditor is known as "making reference to the audit of a component auditor," and it implies a division of responsibility. This is prohibited unless specifically required by law or regulation, a situation so rare it's almost guaranteed to be the wrong answer on the CPA exam.
  • The Logic: The users of the financial statements are relying on the GEP's signature. The GEP's opinion must stand on its own. Assume no reference is the correct answer.

Mastering this framework is easier when you can apply it. Try VoraPrep's adaptive CPA practice questions to drill these steps with realistic exam-style simulations that target your weak areas.

The Big Change: Understanding SAS No. 149 (Effective 2026)

For candidates testing in 2026, you must know the updates from SAS No. 149, Group Audits, which supersedes the old AU-C 600 standard. The core principle of GEP responsibility remains unchanged, but the approach is now more explicitly and robustly risk-based.

Here are the key shifts:

Area of FocusOld Approach (AU-C 600)New Approach (SAS No. 149 - Effective Dec 2025)
Core PrincipleGEP responsibility, with a somewhat prescriptive model for significant components.Still GEP responsibility, but now driven by a holistic, scalable risk assessment. The GEP's involvement is proportional to the risk.
GEP InvolvementPrescribed a set menu of work effort for significant components (e.g., audit of financial info, specified procedures).More scalable and principles-based. The nature, timing, and extent of the GEP's involvement with a component auditor's work depends directly on the assessed risks associated with that component.
Acceptance & ContinuanceGEP assessed if they could get sufficient evidence.Strengthens these requirements. The GEP must explicitly determine if restrictions on access to information or people would prevent them from obtaining sufficient appropriate audit evidence before accepting the engagement.
DocumentationRequired documentation of significant components and the work performed.Enhances documentation requirements to better show the linkage between assessed risks at the component level, the GEP's involvement, and the audit procedures performed. Examiners want to see your thought process.
What this means for you: Exam questions will mirror this risk-based thinking. Instead of just asking "Is this a significant component? Yes or No?", a simulation might ask, "Given the heightened risk of fraud in the Euro Solutions subsidiary's revenue cycle, what is the most appropriate level of GEP involvement?" The logic is the same—more risk equals more GEP involvement—but the framework is more dynamic and requires more judgment.

Worked Example: How to Solve a Group Audit Simulation

Let's apply this thinking to a classic AUD exam scenario.

---

Scenario: Global Tech Corp. (2026 Audit)

You are the Group Engagement Partner (GEP) for the audit of Global Tech Corp., a U.S. company. Global Tech has two main subsidiaries:

  1. Innovate Inc.: A wholly-owned U.S. subsidiary representing 70% of consolidated assets. Your firm is also auditing Innovate Inc. directly.
  2. Euro Solutions SARL: A wholly-owned French subsidiary representing 30% of consolidated assets. Euro Solutions is audited by a local French firm, "Paris Auditors." You have evaluated Paris Auditors and found them to be competent and independent.
Key Information:
  • You have set group materiality for Global Tech at $10 million.
  • You have set group performance materiality at $7.5 million.
  • You have set component performance materiality for Euro Solutions at $4 million.
  • During their audit, Paris Auditors identified an uncorrected misstatement in Euro Solutions' inventory valuation of $4.5 million. Paris Auditors correctly concluded this was material to Euro Solutions' individual financial statements.
  • Global Tech management refuses to correct the $4.5 million misstatement in the consolidated financial statements.
Question: As the GEP for Global Tech Corp., what type of audit opinion should you issue on the consolidated financial statements, and should you reference Paris Auditors in your report?

---

Thinking Through the Problem Like a CPA

1. Identify the Core Issue: There's a known, uncorrected misstatement of $4.5 million originating from a component. Management refuses to book the adjustment. This is a departure from GAAP. 2. Evaluate Materiality at Each Level (The Professional's Approach):
  • Component Level: The misstatement is $4.5 million. The component performance materiality for Euro Solutions is $4 million. Since $4.5M > $4.0M, the misstatement is material at the component level. This is why Paris Auditors correctly identified it and were required to report it to you, the GEP.
  • The Common Trap: A candidate might stop here or get confused. They might compare the $4.5M only to the big group materiality of $10M and incorrectly conclude it's "not a big deal."
  • Group Level (The Right Way): As the GEP, your opinion is on the group financials. You must evaluate the effect of this uncorrected misstatement on the group. You aggregate all known uncorrected misstatements (in this case, just the $4.5M) and compare the total to group performance materiality.
  • Analysis: The total uncorrected misstatement is $4.5 million. Group performance materiality is $7.5 million. Since $4.5M is less than $7.5M, it's not quantitatively material on its own. However, it is clearly not trivial. It represents 60% of group performance materiality. Professional standards require the auditor to use judgment. A known GAAP departure of this magnitude is almost certainly considered material, especially as it could impact key covenants or metrics. For exam purposes, a known and uncorrected management-refused adjustment of this size relative to performance materiality should be treated as material.
3. Determine the Impact on the Group Opinion:
  • You have a material, uncorrected misstatement due to a departure from GAAP (incorrect inventory valuation).
  • Is the misstatement pervasive? A misstatement is pervasive if it's not confined to specific accounts or if it represents a substantial portion of the financials. This error is confined to inventory and cost of goods sold. It's material, but not pervasive.
  • Conclusion: A material but not pervasive misstatement leads to a qualified ("except for") opinion. If the misstatement were so large it rendered the entire financial statements misleading (e.g., $15 million), an adverse opinion would be appropriate.
4. Address the Reporting Trap (Referencing the Component Auditor):
  • The Tempting Wrong Answer: "Issue a qualified opinion and reference the work of Paris Auditors to explain the source of the misstatement." This seems logical and transparent. It is also completely wrong.
  • The Correct Answer: You are the GEP. You are solely responsible. You do not share or deflect that responsibility by naming Paris Auditors in your report. The qualification is based on your conclusion that the group financial statements are materially misstated, regardless of who found the error.
  • Final Decision: You issue a qualified opinion on the Global Tech Corp. consolidated financial statements and you do not reference Paris Auditors.

This step-by-step process is the key to getting these questions right. It demonstrates the judgment and application of principles the exam demands. Understanding the different levels of responsibility is a core part of what VoraPrep's info page on the CPA Exam covers in our philosophy.

---

Ready to Pass Your CPA Exam?

Don't let complex topics like group audits derail your CPA journey. VoraPrep offers a comprehensive platform designed to help you succeed: over 9,500 practice questions with detailed explanations, an adaptive learning engine that targets your weak areas, and Vory, your 24/7 AI tutor. All starting at just $29/month.

Visit voraprep.com to get started and experience the difference.

Start Your Free 14-Day Trial at voraprep.com →

Frequently asked questions

1. What is a "significant component" in a group audit under SAS No. 149? Under SAS No. 149 (effective for 2026 exams), a significant component is one that is of individual financial significance to the group, or is likely to include significant risks of material misstatement of the group financial statements. The standard emphasizes a risk-based approach; a small component with very high-risk transactions could be deemed "significant." 2. Can the GEP ever blame a component auditor if something goes wrong? No. From a reporting standpoint, the GEP is solely responsible for the group audit opinion. While the GEP's firm may have legal recourse against a negligent component auditor, for the purposes of the audit report and the AUD exam, the buck stops entirely with the GEP. 3. How does the GEP evaluate a component auditor's independence? The GEP must obtain an understanding of the component auditor's compliance with relevant ethical requirements, including independence. This typically involves written confirmations, understanding the other firm's quality control policies, discussing any potential threats to independence, and reviewing their compliance history. 4. What if a component uses IFRS but the group uses U.S. GAAP? The GEP is responsible for ensuring that the component's financial information is adjusted to conform to the group's financial reporting framework (e.g., U.S. GAAP). Auditing these conversion adjustments and related disclosures is a key part of the GEP's audit of the consolidation process. 5. What happens if the GEP can't review a component auditor's work? If the GEP cannot obtain sufficient appropriate audit evidence related to a component—perhaps due to management restrictions or an inability to review the component auditor's work—it constitutes a scope limitation. This would likely lead to a qualified opinion or a disclaimer of opinion on the group financial statements. 6. Is a "joint audit" the same as a group audit with a component auditor? No, they are different. In a joint audit, two separate audit firms are appointed to audit the financial statements and they jointly sign a single audit report, sharing responsibility. In a group audit, only one auditor (the GEP) signs the report and takes full responsibility. 7. What is the best way to study for group audits on the CPA exam? The most effective way to study group audits is to focus on the core principle of GEP responsibility first, then use it as a lens to understand the rules. Instead of memorizing rules in isolation, work through practice simulations, like those in VoraPrep's question bank, to see how materiality, risk assessment, and reporting decisions all flow from the GEP's non-delegable accountability. Drawing out organizational charts for scenarios can also help clarify the relationships between the GEP, components, and component auditors. 8. Why are group audits considered one of the harder topics on the AUD exam? Group audits are challenging because they test judgment and application, not just rote memorization. Questions often involve multiple layers of materiality, complex reporting decisions, and nuanced risk assessments under the new SAS No. 149 framework. The exam creates tempting distractor answers, especially regarding referencing the component auditor, which prey on a superficial understanding of the GEP's ultimate responsibility.
⚡ Instant Knowledge Check · 1-Click Test Drive
AUD-II: Assessing Risk & Developing a Planned Response

Under AICPA AU-C 500 (Audit Evidence) and AU-C 505 (External Confirmations), which of the following forms of audit evidence provides the HIGHEST degree of reliability regarding the existence of accounts receivable?

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CPA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CPA diagnostic + 12-week plan PDF

Start →
CPA 1:1 Prometric Simulator

9,500+ practice questions with instant Socratic feedback