## Revenue Recognition (ASC 606)
The core principle of ASC 606 is to recognize revenue to depict the transfer of promised goods or services to customers in an amount that reflects the consideration the entity expects to be entitled to in exchange for those goods or services. This is achieved through a 5-step model:
## The 5-Step Model
1. Identify the contract with a customer: A contract exists if it has commercial substance, the parties are committed, payment terms are identifiable, and collection is probable.
2. Identify the performance obligations in the contract: A performance obligation is a promise to transfer a distinct good or service to the customer. A good or service is distinct if the customer can benefit from it on its own or with other readily available resources, and it is separately identifiable from other promises in the contract.
3. Determine the transaction price: This is the amount of consideration an entity expects to be entitled to. It includes fixed amounts, but also considers variable consideration (e.g., discounts, rebates, performance bonuses), which must be estimated using either the expected value or most likely amount method, and constrained to prevent significant revenue reversals.
4. Allocate the transaction price to the performance obligations: If a contract has multiple performance obligations, the transaction price is allocated to each distinct obligation based on its standalone selling price (SSP). If SSP is not directly observable, it can be estimated using adjusted market assessment, expected cost plus margin, or residual approaches.
5. Recognize revenue when (or as) the entity satisfies a performance obligation:
## Key Considerations
## Objective and Fundamental Concepts
The primary objective of an audit is to provide reasonable assurance that the financial statements are free from material misstatement, whether due to error or fraud, enabling the auditor to express an opinion on whether the financial statements are presented fairly, in all material respects, in accordance with the applicable financial reporting framework. Reasonable assurance is a high, but not absolute, level of assurance.
Materiality is a cornerstone concept. A misstatement is material if it could reasonably be expected to influence the economic decisions of users. Auditors use professional judgment to determine materiality, which impacts the nature, timing, and extent of audit procedures.
Audit risk is the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. It's composed of three risks:
The auditor controls detection risk through the nature, timing, and extent of substantive procedures.
## Risk Assessment and Procedures
Auditors perform risk assessment procedures to identify and assess risks of material misstatement (RMM) at the financial statement and assertion levels. This involves understanding the entity and its environment, including its internal control system. A strong understanding of internal control helps auditors design appropriate audit procedures, as effective controls reduce control risk.
Based on the assessed RMM, auditors design and perform further audit procedures, which include tests of controls (if applicable) and substantive procedures. Substantive procedures are performed to detect material misstatements and comprise tests of details (transactions, balances, disclosures) and substantive analytical procedures. Audit evidence must be sufficient and appropriate to support the audit opinion.
## Audit Opinions and Responsibilities
The auditor's report communicates the audit opinion. The four types of opinions are:
Throughout the audit, auditors must maintain professional skepticism—an attitude that includes a questioning mind and a critical assessment of audit evidence. Independence in fact and appearance is also paramount, ensuring objectivity and integrity.
## Individual Taxation Fundamentals
## Property Transactions
## Tax Procedures & Circular 230
## Ethics and Professional Responsibilities for CPAs
The CPA Exam heavily emphasizes the AICPA Code of Professional Conduct, which guides members in public practice, business, and other roles. It comprises six aspirational Principles (Responsibilities, Public Interest, Integrity, Objectivity & Independence, Due Care, Scope & Nature of Services) and enforceable Rules with specific Interpretations. A Conceptual Framework helps identify, evaluate, and mitigate threats to compliance with the rules.
Independence is paramount for attest engagements (audits, reviews). It requires both independence in fact (state of mind) and independence in appearance (avoiding circumstances that would cause a reasonable third party to conclude independence is impaired). Threats to independence include self-review, advocacy, adverse interest, familiarity, undue influence, self-interest, and management participation. Safeguards (profession-wide, client-specific, firm-specific) must be applied to eliminate or reduce threats to an acceptable level. Certain non-attest services, financial interests, and employment relationships can impair independence.
All CPAs must maintain Integrity and Objectivity. Integrity demands honesty and candor, while objectivity requires impartiality and freedom from conflicts of interest. Due Care mandates competence and diligence in performing professional services, including proper planning, supervision, and obtaining sufficient data. Confidentiality prohibits disclosing client information without specific consent, unless legally compelled (e.g., subpoena, peer review, ethics investigation). Advertising must not be false, misleading, or deceptive. Commissions and referral fees are generally prohibited for attest clients.
The Sarbanes-Oxley Act (SOX) significantly impacted auditor independence and corporate governance. Key provisions include the creation of the Public Company Accounting Oversight Board (PCAOB) to oversee auditors of public companies, rules prohibiting certain non-audit services for attest clients, mandatory partner rotation, and a one-year "cooling-off" period for former audit firm employees joining a client in a key financial reporting role. SOX also enhanced corporate responsibility, requiring management certifications of financial statements and establishing audit committee responsibilities.
Treasury Department Circular 230 governs the practice of tax professionals before the IRS, outlining duties and restrictions, including due diligence requirements and best practices for tax advisors.
## Contracts
A contract is a legally enforceable agreement. Essential elements include: Offer, Acceptance, Consideration (a bargained-for exchange), Capacity (competent parties), and Legality (a lawful purpose). The Statute of Frauds requires certain contracts to be in writing to be enforceable, such as contracts for the sale of land, contracts that cannot be performed within one year, and contracts for the sale of goods over $500 (UCC). Remedies for breach include monetary damages (compensatory, consequential), specific performance (for unique goods), or rescission. The Parol Evidence Rule prevents the introduction of prior or contemporaneous oral agreements that contradict a fully integrated written contract.
## Sales (UCC Article 2)
The Uniform Commercial Code (UCC) Article 2 governs contracts for the sale of goods. Unlike common law, the UCC is more flexible, especially between merchants. Key differences include:
## Agency
An agency relationship arises when one person (the agent) acts on behalf of another (the principal), subject to the principal's control. Agents owe fiduciary duties to their principal, including loyalty, obedience, care, and accounting. A principal is generally liable for an agent's contracts made within the scope of actual or apparent authority. A principal may also be liable for an agent's torts committed within the scope of employment (respondeat superior).
## Business Structures
## Debtor-Creditor Relationships
## Information Systems and Controls (ISC) Overview
The ISC section of the CPA exam focuses on the role of technology in business, emphasizing how information systems are controlled and secured to ensure data integrity, confidentiality, and availability. Understanding IT General Controls (ITGCs) and Application Controls is fundamental. ITGCs apply to all systems and include controls over program development, program changes, computer operations, and access to programs and data. Application controls are specific to individual applications and ensure the completeness, accuracy, authorization, and validity of data input, processing, and output.
## Information Security and Access Management
Information security is paramount. Key concepts include confidentiality (preventing unauthorized disclosure), integrity (maintaining accuracy and completeness), and availability (ensuring access when needed). Access controls restrict user access to information and resources based on identity. This involves authentication (verifying identity, e.g., passwords, multifactor authentication) and authorization (granting specific permissions). Other security measures include encryption (transforming data to protect it), firewalls (network security systems), and Intrusion Detection/Prevention Systems (IDS/IPS).
## System and Organization Controls (SOC) Reports
SOC reports are critical for service organizations to demonstrate internal control effectiveness. A SOC 1 report focuses on controls relevant to a user entity's financial reporting (ICFR). A SOC 2 report addresses controls related to security, availability, processing integrity, confidentiality, or privacy (Trust Services Criteria). Both SOC 1 and SOC 2 can be Type 1 (description of system and suitability of controls at a point in time) or Type 2 (includes Type 1 plus operating effectiveness over a period).
## Business Continuity and Disaster Recovery
Organizations must plan for disruptions. Business Continuity Planning (BCP) ensures essential business functions continue during and after a disaster. Disaster Recovery Planning (DRP) focuses specifically on restoring IT systems and infrastructure. Key metrics include Recovery Time Objective (RTO), the maximum acceptable downtime, and Recovery Point Objective (RPO), the maximum acceptable data loss. Strategies include data backups, redundant systems, and offsite storage.
## Tax Compliance and Planning (TCP) Revision Notes
The TCP section of the CPA Exam assesses your understanding of federal tax principles, compliance, and planning for individuals, businesses, and other entities. Mastery requires a solid grasp of income inclusions, deductions, credits, and entity-specific rules.
## Individual Income Taxation
Gross Income includes all income from whatever source derived, unless specifically excluded. Common inclusions are wages, interest, dividends, business income, rents, royalties, and capital gains. Exclusions include tax-exempt interest (e.g., municipal bonds), gifts, inheritances, and certain fringe benefits.
Deductions for Adjusted Gross Income (AGI), also known as "above-the-line" deductions, reduce gross income to arrive at AGI. Examples include self-employment tax (one-half), IRA contributions (subject to limits), student loan interest, and alimony paid (for divorce agreements before 2019).
Deductions from AGI are either the standard deduction or itemized deductions, whichever is greater. Common itemized deductions include medical expenses (exceeding 7.5% AGI), state and local taxes (SALT) up to $10,000, home mortgage interest, and charitable contributions.
Tax Credits directly reduce tax liability dollar-for-dollar, making them more valuable than deductions. Examples include the Child Tax Credit, Earned Income Tax Credit, and education credits.
## Business Entity Taxation
Understanding the tax implications of different business structures is crucial.
## Property Transactions
Basis is generally the cost of acquiring property and is crucial for calculating gain or loss on disposition. Adjusted basis accounts for capital improvements and depreciation. Depreciation (e.g., MACRS for tangible property) allows for the recovery of the cost of assets over their useful life. When depreciable property is sold, recapture rules (Sections 1245 and 1250) may reclassify a portion of the gain from capital gain to ordinary income. Section 1231 assets are depreciable property and real property used in a trade or business held over one year. Net Section 1231 gains are treated as long-term capital gains, while net Section 1231 losses are treated as ordinary losses.
## Tax Planning and Compliance
Estimated Taxes must be paid by individuals and corporations if they expect to owe a certain amount of tax. Penalties apply for underpayment. The statute of limitations for assessment of tax is generally three years from the later of the due date of the return or the date the return was filed. For substantial understatement of income (over 25% gross income), it's six years. No statute of limitations for fraud or failure to file.
## Business Analysis and Reporting (BAR) Overview
The BAR section of the CPA Exam assesses a candidate's ability to apply analytical skills in financial management, data analytics, operations management, and enterprise risk management. It focuses on understanding how these areas contribute to business decision-making and performance.
## Financial Management
Financial Management involves optimizing an organization's financial resources to maximize shareholder wealth. Key topics include capital budgeting, which evaluates long-term investment projects. Techniques like Net Present Value (NPV), Internal Rate of Return (IRR), and Payback Period are used. NPV is generally preferred as it considers the time value of money and provides a direct measure of value creation. Understanding the Weighted Average Cost of Capital (WACC) is crucial, as it represents the average rate of return a company expects to pay to finance its assets. Working capital management focuses on efficiently managing current assets (cash, accounts receivable, inventory) and current liabilities (accounts payable) to ensure liquidity and profitability.
## Data Analytics
Data Analytics is the process of examining data to uncover insights and support decision-making. There are four main types:
Data visualization is essential for effectively communicating complex data insights. CPAs must also understand data governance, data quality, and the ethical considerations of data use.
## Operations Management
Operations Management deals with the design, operation, and improvement of the systems that create and deliver a company's primary products and services. Supply Chain Management (SCM) optimizes the flow of goods, services, and information from suppliers to customers. Concepts like Lean Manufacturing focus on eliminating waste (e.g., overproduction, waiting, defects) to improve efficiency and value. Six Sigma aims to reduce defects and variability in processes to achieve near-perfect quality. Other areas include capacity planning, forecasting, and total quality management (TQM).
## Enterprise Risk Management (ERM)
The COSO ERM Framework provides a comprehensive approach for organizations to manage risks that could affect their ability to achieve objectives. It emphasizes integrating risk management into strategy-setting and performance. Key components include governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting. CPAs play a role in identifying, assessing, and responding to risks, ensuring alignment with the organization's risk appetite.