← Certified Public Accountant (CPA) Exam
Test yourself →

Financial Accounting and Reporting (FAR)

## Revenue Recognition (ASC 606)

The core principle of ASC 606 is to recognize revenue to depict the transfer of promised goods or services to customers in an amount that reflects the consideration the entity expects to be entitled to in exchange for those goods or services. This is achieved through a 5-step model:

## The 5-Step Model

1. Identify the contract with a customer: A contract exists if it has commercial substance, the parties are committed, payment terms are identifiable, and collection is probable.

2. Identify the performance obligations in the contract: A performance obligation is a promise to transfer a distinct good or service to the customer. A good or service is distinct if the customer can benefit from it on its own or with other readily available resources, and it is separately identifiable from other promises in the contract.

3. Determine the transaction price: This is the amount of consideration an entity expects to be entitled to. It includes fixed amounts, but also considers variable consideration (e.g., discounts, rebates, performance bonuses), which must be estimated using either the expected value or most likely amount method, and constrained to prevent significant revenue reversals.

4. Allocate the transaction price to the performance obligations: If a contract has multiple performance obligations, the transaction price is allocated to each distinct obligation based on its standalone selling price (SSP). If SSP is not directly observable, it can be estimated using adjusted market assessment, expected cost plus margin, or residual approaches.

5. Recognize revenue when (or as) the entity satisfies a performance obligation:

  • Over time: Revenue is recognized over time if one of three criteria is met: (a) the customer simultaneously receives and consumes the benefits, (b) the entity creates or enhances an asset the customer controls, or (c) the entity does not create an asset with an alternative use, and has an enforceable right to payment for performance completed to date.
  • At a point in time: If none of the over-time criteria are met, revenue is recognized at a point in time when the customer obtains control of the asset or service. Indicators of control include the entity having a right to payment, the customer having legal title, physical possession, significant risks and rewards, and customer acceptance.

## Key Considerations

  • Principal vs. Agent: A principal recognizes revenue on a gross basis (total consideration), while an agent recognizes revenue on a net basis (commission). The key is whether the entity controls the good or service before transferring it to the customer.
  • Contract Assets & Liabilities: A contract asset arises when an entity has transferred goods/services but payment is conditional on something other than the passage of time. A contract liability (deferred revenue) arises when an entity has received payment but has not yet transferred the goods/services.
  • ASC 606's core principle is to recognize revenue depicting the transfer of goods/services for the expected consideration.
  • The Revenue Recognition model consists of 5 steps: Identify contract, Identify POs, Determine transaction price, Allocate price, Recognize revenue.
  • A performance obligation is distinct if the customer can benefit from it on its own or with other resources, and it's separately identifiable.
  • Variable consideration must be estimated and constrained to prevent significant revenue reversals.
  • Allocate transaction price to performance obligations based on their standalone selling prices (SSP).
  • Revenue is recognized 'over time' if the customer simultaneously consumes benefits, controls an asset being created/enhanced, or the entity has a right to payment for work done without alternative use.
  • A principal recognizes revenue gross, while an agent recognizes it net, based on who controls the good/service before transfer.
  • Contract assets arise from satisfied performance obligations where payment is conditional; contract liabilities are for unsatisfied obligations where payment has been received.
What is the core principle of ASC 606 Revenue Recognition?
To recognize revenue depicting the transfer of promised goods or services to customers in an amount that reflects the consideration the entity expects to be entitled to.
tap to reveal
List the 5 steps of the Revenue Recognition model.
1. Identify contract. 2. Identify performance obligations. 3. Determine transaction price. 4. Allocate transaction price. 5. Recognize revenue.
tap to reveal
What makes a good or service 'distinct' for identifying performance obligations?
The customer can benefit from it on its own or with other readily available resources, AND it is separately identifiable from other promises in the contract.
tap to reveal
How should variable consideration be accounted for in determining the transaction price?
Estimate using expected value or most likely amount, and constrain the estimate to prevent significant revenue reversals.
tap to reveal
When is revenue recognized 'over time' according to ASC 606?
When the customer simultaneously receives and consumes benefits, OR the entity creates/enhances an asset the customer controls, OR the entity has a right to payment for performance completed to date and no alternative use for the asset.
tap to reveal
Differentiate between a 'principal' and an 'agent' in revenue recognition.
A principal controls the good/service before transferring it to the customer and recognizes revenue on a gross basis. An agent does not control it and recognizes revenue on a net (commission) basis.
tap to reveal
Define a 'contract asset' under ASC 606.
An entity's right to consideration in exchange for goods or services that the entity has transferred to a customer when that right is conditional on something other than the passage of time (e.g., future performance).
tap to reveal
Define a 'contract liability' under ASC 606.
An entity's obligation to transfer goods or services to a customer for which the entity has received consideration (or an amount of consideration is due) from the customer (also known as deferred revenue).
tap to reveal

Auditing and Attestation (AUD)

## Objective and Fundamental Concepts

The primary objective of an audit is to provide reasonable assurance that the financial statements are free from material misstatement, whether due to error or fraud, enabling the auditor to express an opinion on whether the financial statements are presented fairly, in all material respects, in accordance with the applicable financial reporting framework. Reasonable assurance is a high, but not absolute, level of assurance.

Materiality is a cornerstone concept. A misstatement is material if it could reasonably be expected to influence the economic decisions of users. Auditors use professional judgment to determine materiality, which impacts the nature, timing, and extent of audit procedures.

Audit risk is the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. It's composed of three risks:

  • Inherent Risk (IR): Susceptibility of an assertion to misstatement, assuming no related controls.
  • Control Risk (CR): Risk that a misstatement that could occur will not be prevented or detected by internal controls.
  • Detection Risk (DR): Risk that the auditor's procedures will not detect a misstatement that exists and could be material.

The auditor controls detection risk through the nature, timing, and extent of substantive procedures.

## Risk Assessment and Procedures

Auditors perform risk assessment procedures to identify and assess risks of material misstatement (RMM) at the financial statement and assertion levels. This involves understanding the entity and its environment, including its internal control system. A strong understanding of internal control helps auditors design appropriate audit procedures, as effective controls reduce control risk.

Based on the assessed RMM, auditors design and perform further audit procedures, which include tests of controls (if applicable) and substantive procedures. Substantive procedures are performed to detect material misstatements and comprise tests of details (transactions, balances, disclosures) and substantive analytical procedures. Audit evidence must be sufficient and appropriate to support the audit opinion.

## Audit Opinions and Responsibilities

The auditor's report communicates the audit opinion. The four types of opinions are:

  • Unmodified (Unqualified): Financial statements are presented fairly in all material respects.
  • Qualified: Financial statements are presented fairly "except for" a specific material misstatement or scope limitation that is not pervasive.
  • Adverse: Financial statements are materially misstated and pervasive.
  • Disclaimer: Auditor does not express an opinion due to a pervasive scope limitation or lack of independence.

Throughout the audit, auditors must maintain professional skepticism—an attitude that includes a questioning mind and a critical assessment of audit evidence. Independence in fact and appearance is also paramount, ensuring objectivity and integrity.

  • The objective of an audit is to provide reasonable assurance that financial statements are free from material misstatement.
  • Materiality is a key concept; a misstatement is material if it could influence users' economic decisions.
  • Audit risk = Inherent Risk x Control Risk x Detection Risk, where auditors control Detection Risk.
  • Professional skepticism requires a questioning mind and critical assessment of audit evidence.
  • Independence (in fact and appearance) is essential for auditor objectivity and integrity.
  • An unmodified opinion means financial statements are presented fairly in all material respects.
  • An adverse opinion is issued when financial statements are materially and pervasively misstated.
  • A disclaimer of opinion is issued when the auditor lacks independence or has a pervasive scope limitation.
  • Substantive procedures include tests of details and substantive analytical procedures to detect material misstatements.
What are the three components of audit risk?
Inherent Risk, Control Risk, and Detection Risk.
tap to reveal
Define 'materiality' in the context of an audit.
The magnitude of an omission or misstatement that, individually or in aggregate, could reasonably be expected to influence the economic decisions of users.
tap to reveal
When is an 'Adverse Opinion' issued?
When the financial statements are materially and pervasively misstated.
tap to reveal
What is 'professional skepticism'?
An attitude that includes a questioning mind and a critical assessment of audit evidence.
tap to reveal
What is the primary purpose of an engagement letter?
To document and confirm the auditor's acceptance of the engagement, the objective and scope of the audit, the responsibilities of the auditor and management, and the form of reports.
tap to reveal
What is the auditor's responsibility regarding 'going concern'?
To evaluate whether there is substantial doubt about the entity's ability to continue as a going concern for a reasonable period (typically one year from the financial statement date).
tap to reveal
What are 'substantive procedures'?
Audit procedures performed to detect material misstatements at the assertion level, comprising tests of details and substantive analytical procedures.
tap to reveal
What is the difference between 'sufficiency' and 'appropriateness' of audit evidence?
Sufficiency refers to the quantity of evidence, while appropriateness refers to the quality (relevance and reliability) of evidence.
tap to reveal

Taxation and Regulation (REG)

## Individual Taxation Fundamentals

  • Gross Income (GI): Includes all income from whatever source derived, unless specifically excluded by law. Common inclusions: wages, salaries, business income, interest, dividends, rents, royalties, alimony received (for divorces before 2019). Common exclusions: gifts, inheritances, municipal bond interest, life insurance proceeds, qualified fringe benefits.
  • Deductions for Adjusted Gross Income (AGI): Often called "above-the-line" deductions. These reduce gross income to arrive at AGI. Examples include: IRA contributions (for active participants, subject to income limits), student loan interest, self-employment tax (50%), alimony paid (for divorces before 2019), health savings account (HSA) contributions, and educator expenses. AGI is a crucial benchmark for various limitations.
  • Deductions From AGI: Often called "below-the-line" deductions. These are either the standard deduction or itemized deductions.
  • Standard Deduction: A fixed amount based on filing status, age, and blindness. Most taxpayers choose this unless itemized deductions exceed it.
  • Itemized Deductions: Include medical expenses (exceeding 7.5% AGI threshold), state and local taxes (SALT) capped at $10,000, home mortgage interest, charitable contributions (subject to AGI limits), and casualty/theft losses (only federally declared disaster areas, exceeding 10% AGI and $100 floor). Miscellaneous itemized deductions subject to 2% AGI floor were eliminated by TCJA.

## Property Transactions

  • Basis: The cost of an asset for tax purposes. It's used to determine gain or loss on disposition.
  • Original Basis: Generally cost + expenses to acquire and prepare for use.
  • Adjusted Basis: Original basis +/- capital additions (improvements) - capital recoveries (depreciation, casualty losses).
  • Gift Basis: Generally the donor's adjusted basis. If FMV at gift date is lower, a dual basis rule applies for gain/loss determination.
  • Inherited Basis: Generally the fair market value (FMV) at the date of death (or alternate valuation date). This is often a "step-up" in basis.
  • Realized Gain/Loss: Amount Realized (AR) - Adjusted Basis (AB). AR includes cash received, FMV of property received, and debt relief, minus selling expenses.
  • Recognized Gain/Loss: The portion of realized gain/loss that is included in taxable income. Generally, all realized gains are recognized unless a specific provision allows deferral (e.g., like-kind exchange). Losses are only recognized if allowed by law (e.g., personal use property losses are not deductible).

## Tax Procedures & Circular 230

  • Statute of Limitations:
  • General Rule: 3 years from the later of the due date of the return or the date the return was filed.
  • Substantial Understatement of Income: 6 years if gross income is omitted by more than 25%.
  • Fraudulent Return / No Return: No statute of limitations.
  • Circular 230: Regulations governing practice before the IRS. It outlines duties and restrictions for tax practitioners (attorneys, CPAs, enrolled agents).
  • Key duties: Exercise due diligence, promptly submit records, advise clients of penalties, return client records.
  • Prohibitions: Unconscionable fees, false advertising, negotiating client refund checks.
  • Sanctions: Censure, suspension, or disbarment from practice before the IRS.
  • Municipal bond interest is generally excluded from gross income.
  • Alimony received/paid is only taxable/deductible for divorces executed before 2019.
  • The standard deduction is chosen over itemized deductions if it results in a lower taxable income.
  • Inherited property generally receives a "step-up" in basis to its fair market value at death.
  • Losses on the sale of personal-use property are not deductible.
  • The general statute of limitations for IRS assessment is 3 years from the later of the due date or filing date.
  • Circular 230 governs the practice of CPAs, attorneys, and EAs before the IRS.
  • The SALT deduction for itemized deductions is capped at $10,000 per household.
What is the general rule for the basis of inherited property?
Fair Market Value (FMV) at the date of death (or alternate valuation date).
tap to reveal
What is the "above-the-line" deduction for a portion of self-employment tax?
50% of self-employment tax.
tap to reveal
What is the statute of limitations for IRS assessment if a taxpayer omits more than 25% of gross income?
6 years.
tap to reveal
Are losses on the sale of personal-use property deductible?
No, losses on personal-use property are not deductible.
tap to reveal
What is the maximum deduction for state and local taxes (SALT) for itemizing taxpayers?
$10,000 per household.
tap to reveal
Under Circular 230, what is a key prohibition regarding client refund checks?
A practitioner may not negotiate a client's refund check.
tap to reveal
What is the tax treatment of gifts and inheritances received by an individual?
Gifts and inheritances are generally excluded from gross income.
tap to reveal
What is the primary purpose of Adjusted Gross Income (AGI)?
AGI is a crucial benchmark used to calculate various limitations for deductions, credits, and other tax benefits.
tap to reveal

Ethics and Professional Responsibilities

## Ethics and Professional Responsibilities for CPAs

The CPA Exam heavily emphasizes the AICPA Code of Professional Conduct, which guides members in public practice, business, and other roles. It comprises six aspirational Principles (Responsibilities, Public Interest, Integrity, Objectivity & Independence, Due Care, Scope & Nature of Services) and enforceable Rules with specific Interpretations. A Conceptual Framework helps identify, evaluate, and mitigate threats to compliance with the rules.

Independence is paramount for attest engagements (audits, reviews). It requires both independence in fact (state of mind) and independence in appearance (avoiding circumstances that would cause a reasonable third party to conclude independence is impaired). Threats to independence include self-review, advocacy, adverse interest, familiarity, undue influence, self-interest, and management participation. Safeguards (profession-wide, client-specific, firm-specific) must be applied to eliminate or reduce threats to an acceptable level. Certain non-attest services, financial interests, and employment relationships can impair independence.

All CPAs must maintain Integrity and Objectivity. Integrity demands honesty and candor, while objectivity requires impartiality and freedom from conflicts of interest. Due Care mandates competence and diligence in performing professional services, including proper planning, supervision, and obtaining sufficient data. Confidentiality prohibits disclosing client information without specific consent, unless legally compelled (e.g., subpoena, peer review, ethics investigation). Advertising must not be false, misleading, or deceptive. Commissions and referral fees are generally prohibited for attest clients.

The Sarbanes-Oxley Act (SOX) significantly impacted auditor independence and corporate governance. Key provisions include the creation of the Public Company Accounting Oversight Board (PCAOB) to oversee auditors of public companies, rules prohibiting certain non-audit services for attest clients, mandatory partner rotation, and a one-year "cooling-off" period for former audit firm employees joining a client in a key financial reporting role. SOX also enhanced corporate responsibility, requiring management certifications of financial statements and establishing audit committee responsibilities.

Treasury Department Circular 230 governs the practice of tax professionals before the IRS, outlining duties and restrictions, including due diligence requirements and best practices for tax advisors.

  • The AICPA Code of Professional Conduct includes aspirational Principles and enforceable Rules.
  • Independence is required for attest services (audits, reviews) and comprises 'in fact' and 'in appearance'.
  • The Sarbanes-Oxley Act (SOX) created the PCAOB to oversee auditors of public companies.
  • SOX prohibits specific non-audit services for public company audit clients and mandates partner rotation.
  • CPAs must maintain confidentiality of client information unless legally compelled or with client consent.
  • Integrity and Objectivity apply to all CPAs, requiring honesty, candor, and freedom from conflicts of interest.
  • Due Care requires competence, diligence, and proper planning in performing professional services.
  • Treasury Department Circular 230 governs the practice of tax professionals before the IRS.
What are the two types of independence required for attest engagements?
Independence in fact (state of mind) and independence in appearance (avoiding circumstances that would cause a reasonable third party to conclude independence is impaired).
tap to reveal
Which body was created by the Sarbanes-Oxley Act (SOX) to oversee auditors of public companies?
The Public Company Accounting Oversight Board (PCAOB).
tap to reveal
Under what circumstances can a CPA disclose confidential client information without the client's specific consent?
Only if required by a valid subpoena or summons, for a peer review, or in response to an ethics investigation (AICPA/State Board).
tap to reveal
What AICPA Code principle requires CPAs to be impartial and free of conflicts of interest?
Objectivity.
tap to reveal
What is the primary purpose of Treasury Department Circular 230?
To regulate the practice of tax professionals before the Internal Revenue Service (IRS).
tap to reveal
Name two types of threats to independence identified by the AICPA Conceptual Framework.
Self-review, advocacy, adverse interest, familiarity, undue influence, self-interest, management participation (any two).
tap to reveal
Are commissions and referral fees generally permitted for a CPA providing attest services to a client?
No, they are generally prohibited for clients for whom the CPA performs attest services.
tap to reveal
What is the "cooling-off" period under SOX for a former audit firm employee joining an audit client in a key financial reporting oversight role?
One year.
tap to reveal

Business Law

## Contracts

A contract is a legally enforceable agreement. Essential elements include: Offer, Acceptance, Consideration (a bargained-for exchange), Capacity (competent parties), and Legality (a lawful purpose). The Statute of Frauds requires certain contracts to be in writing to be enforceable, such as contracts for the sale of land, contracts that cannot be performed within one year, and contracts for the sale of goods over $500 (UCC). Remedies for breach include monetary damages (compensatory, consequential), specific performance (for unique goods), or rescission. The Parol Evidence Rule prevents the introduction of prior or contemporaneous oral agreements that contradict a fully integrated written contract.

## Sales (UCC Article 2)

The Uniform Commercial Code (UCC) Article 2 governs contracts for the sale of goods. Unlike common law, the UCC is more flexible, especially between merchants. Key differences include:

  • Offer & Acceptance: An offer can be accepted by any reasonable means. A firm offer by a merchant is irrevocable for a stated time (max 3 months) without consideration.
  • Modification: Requires no new consideration if made in good faith.
  • Risk of Loss: Generally passes to the buyer upon delivery to a common carrier (shipment contract) or upon tender of delivery at destination (destination contract). If goods are non-conforming, risk remains with the seller.
  • Warranties: Express warranties (affirmations of fact, descriptions) and implied warranties (merchantability, fitness for a particular purpose) protect buyers.

## Agency

An agency relationship arises when one person (the agent) acts on behalf of another (the principal), subject to the principal's control. Agents owe fiduciary duties to their principal, including loyalty, obedience, care, and accounting. A principal is generally liable for an agent's contracts made within the scope of actual or apparent authority. A principal may also be liable for an agent's torts committed within the scope of employment (respondeat superior).

## Business Structures

  • Limited Liability Company (LLC): Offers owners (members) limited liability (personal assets protected from business debts) and pass-through taxation (profits taxed only at the owner level). It combines corporate-like limited liability with partnership-like tax treatment.
  • Corporation: A separate legal entity. Owners (shareholders) have limited liability. Subject to double taxation (corporate profits taxed, then dividends to shareholders taxed). Requires more formal compliance.

## Debtor-Creditor Relationships

  • Suretyship: A surety is primarily liable for the debt of another, meaning the creditor can demand payment directly from the surety without first pursuing the principal debtor.
  • Guaranty: A guarantor is secondarily liable; the creditor must first attempt to collect from the principal debtor before seeking payment from the guarantor.
  • The Statute of Frauds requires certain contracts, like land sales or goods over $500, to be in writing.
  • UCC Article 2 governs sales of goods, while common law applies to services and real estate.
  • A surety is primarily liable for a debt, while a guarantor is secondarily liable.
  • LLCs provide members with limited liability and pass-through taxation.
  • Agents owe fiduciary duties (loyalty, obedience, care) to their principals.
  • For non-conforming goods, the risk of loss generally remains with the seller.
  • A valid contract requires offer, acceptance, consideration, capacity, and legality.
  • The Parol Evidence Rule prevents contradicting a fully integrated written contract with prior oral agreements.
What are the five essential elements of a legally enforceable contract?
Offer, Acceptance, Consideration, Capacity, and Legality.
tap to reveal
Under the UCC, when can an offer by a merchant be irrevocable without consideration?
A "firm offer" by a merchant, in writing and signed, is irrevocable for the stated time (or a reasonable time, up to 3 months).
tap to reveal
What is the primary difference in liability between a surety and a guarantor?
A surety is primarily liable (creditor can demand payment immediately), while a guarantor is secondarily liable (creditor must first pursue the principal debtor).
tap to reveal
What are the key advantages of a Limited Liability Company (LLC) for its owners?
Limited liability (protection of personal assets) and pass-through taxation (avoiding double taxation).
tap to reveal
Name three fiduciary duties an agent owes to their principal.
Loyalty, Obedience, and Care (also Accounting and Notification).
tap to reveal
What is the "Statute of Frauds"?
A legal principle requiring certain types of contracts (e.g., land, goods > $500, contracts not performable within 1 year) to be in writing to be enforceable.
tap to reveal
When does the risk of loss generally pass from seller to buyer in a UCC "shipment contract"?
When the seller delivers the goods to the common carrier.
tap to reveal
What does the Parol Evidence Rule prevent?
The introduction of prior or contemporaneous oral agreements that contradict a fully integrated written contract.
tap to reveal

Information Systems and Controls (ISC)

## Information Systems and Controls (ISC) Overview

The ISC section of the CPA exam focuses on the role of technology in business, emphasizing how information systems are controlled and secured to ensure data integrity, confidentiality, and availability. Understanding IT General Controls (ITGCs) and Application Controls is fundamental. ITGCs apply to all systems and include controls over program development, program changes, computer operations, and access to programs and data. Application controls are specific to individual applications and ensure the completeness, accuracy, authorization, and validity of data input, processing, and output.

## Information Security and Access Management

Information security is paramount. Key concepts include confidentiality (preventing unauthorized disclosure), integrity (maintaining accuracy and completeness), and availability (ensuring access when needed). Access controls restrict user access to information and resources based on identity. This involves authentication (verifying identity, e.g., passwords, multifactor authentication) and authorization (granting specific permissions). Other security measures include encryption (transforming data to protect it), firewalls (network security systems), and Intrusion Detection/Prevention Systems (IDS/IPS).

## System and Organization Controls (SOC) Reports

SOC reports are critical for service organizations to demonstrate internal control effectiveness. A SOC 1 report focuses on controls relevant to a user entity's financial reporting (ICFR). A SOC 2 report addresses controls related to security, availability, processing integrity, confidentiality, or privacy (Trust Services Criteria). Both SOC 1 and SOC 2 can be Type 1 (description of system and suitability of controls at a point in time) or Type 2 (includes Type 1 plus operating effectiveness over a period).

## Business Continuity and Disaster Recovery

Organizations must plan for disruptions. Business Continuity Planning (BCP) ensures essential business functions continue during and after a disaster. Disaster Recovery Planning (DRP) focuses specifically on restoring IT systems and infrastructure. Key metrics include Recovery Time Objective (RTO), the maximum acceptable downtime, and Recovery Point Objective (RPO), the maximum acceptable data loss. Strategies include data backups, redundant systems, and offsite storage.

  • IT General Controls (ITGCs) apply to all systems, while Application Controls are specific to individual applications.
  • The CIA triad in information security stands for Confidentiality, Integrity, and Availability.
  • Authentication verifies identity, while Authorization grants specific permissions.
  • SOC 1 reports focus on controls relevant to financial reporting (ICFR).
  • SOC 2 reports address controls related to Security, Availability, Processing Integrity, Confidentiality, and Privacy (Trust Services Criteria).
  • A Type 2 SOC report includes both the description of controls and their operating effectiveness over a period.
  • Recovery Time Objective (RTO) is the maximum acceptable downtime, and Recovery Point Objective (RPO) is the maximum acceptable data loss.
  • Segregation of Duties (SoD) is a key internal control to prevent fraud and errors by dividing responsibilities.
What are the three core principles of information security (the CIA triad)?
Confidentiality, Integrity, and Availability.
tap to reveal
Distinguish between IT General Controls (ITGCs) and Application Controls.
ITGCs apply to all systems (e.g., access, program changes), while Application Controls are specific to an application's input, processing, and output.
tap to reveal
What is the primary focus of a SOC 1 report?
Controls relevant to a user entity's financial reporting (ICFR).
tap to reveal
What is the difference between a Type 1 and a Type 2 SOC report?
Type 1 describes the system and suitability of controls at a point in time. Type 2 includes Type 1 plus the operating effectiveness of controls over a period.
tap to reveal
Define Recovery Time Objective (RTO).
The maximum acceptable duration of time that a system or application can be down after a disaster or disruption.
tap to reveal
What control prevents a single individual from perpetrating and concealing fraud?
Segregation of Duties (SoD).
tap to reveal
What is the purpose of a firewall?
To monitor and control incoming and outgoing network traffic based on predetermined security rules, acting as a barrier between trusted and untrusted networks.
tap to reveal
What is multifactor authentication (MFA)?
An authentication method requiring users to verify their identity using two or more distinct factors (e.g., something you know, something you have, something you are).
tap to reveal

Tax Compliance and Planning (TCP)

## Tax Compliance and Planning (TCP) Revision Notes

The TCP section of the CPA Exam assesses your understanding of federal tax principles, compliance, and planning for individuals, businesses, and other entities. Mastery requires a solid grasp of income inclusions, deductions, credits, and entity-specific rules.

## Individual Income Taxation

Gross Income includes all income from whatever source derived, unless specifically excluded. Common inclusions are wages, interest, dividends, business income, rents, royalties, and capital gains. Exclusions include tax-exempt interest (e.g., municipal bonds), gifts, inheritances, and certain fringe benefits.

Deductions for Adjusted Gross Income (AGI), also known as "above-the-line" deductions, reduce gross income to arrive at AGI. Examples include self-employment tax (one-half), IRA contributions (subject to limits), student loan interest, and alimony paid (for divorce agreements before 2019).

Deductions from AGI are either the standard deduction or itemized deductions, whichever is greater. Common itemized deductions include medical expenses (exceeding 7.5% AGI), state and local taxes (SALT) up to $10,000, home mortgage interest, and charitable contributions.

Tax Credits directly reduce tax liability dollar-for-dollar, making them more valuable than deductions. Examples include the Child Tax Credit, Earned Income Tax Credit, and education credits.

## Business Entity Taxation

Understanding the tax implications of different business structures is crucial.

  • Sole Proprietorships and Partnerships (including LLCs taxed as partnerships) are pass-through entities. Income and losses are reported on the owners' individual tax returns (Form 1040, Schedule C or K-1). The entity itself generally does not pay income tax.
  • S Corporations are also pass-through entities, avoiding corporate-level tax. Income and losses pass through to shareholders based on their ownership percentage, reported on Schedule K-1.
  • C Corporations are subject to double taxation: the corporation pays tax on its profits, and shareholders pay tax again on dividends received. C-corps file Form 1120.

## Property Transactions

Basis is generally the cost of acquiring property and is crucial for calculating gain or loss on disposition. Adjusted basis accounts for capital improvements and depreciation. Depreciation (e.g., MACRS for tangible property) allows for the recovery of the cost of assets over their useful life. When depreciable property is sold, recapture rules (Sections 1245 and 1250) may reclassify a portion of the gain from capital gain to ordinary income. Section 1231 assets are depreciable property and real property used in a trade or business held over one year. Net Section 1231 gains are treated as long-term capital gains, while net Section 1231 losses are treated as ordinary losses.

## Tax Planning and Compliance

Estimated Taxes must be paid by individuals and corporations if they expect to owe a certain amount of tax. Penalties apply for underpayment. The statute of limitations for assessment of tax is generally three years from the later of the due date of the return or the date the return was filed. For substantial understatement of income (over 25% gross income), it's six years. No statute of limitations for fraud or failure to file.

  • The State and Local Tax (SALT) deduction is capped at $10,000 for individuals.
  • C Corporations are subject to double taxation on corporate profits and shareholder dividends.
  • Pass-through entities (S-corps, partnerships) generally avoid entity-level income tax.
  • Tax credits provide a dollar-for-dollar reduction in tax liability, more valuable than deductions.
  • Net Section 1231 gains are treated as long-term capital gains, while net losses are ordinary.
  • The general statute of limitations for tax assessment is three years from filing or due date.
  • Alimony paid is deductible for divorce agreements executed before January 1, 2019.
  • Modified Accelerated Cost Recovery System (MACRS) is the standard depreciation method for tax purposes.
What is the primary difference in taxation between a C Corporation and an S Corporation?
C Corporations face double taxation (corporate and shareholder level), while S Corporations are pass-through entities, avoiding corporate-level tax.
tap to reveal
What is the general statute of limitations for the IRS to assess additional tax?
Generally three years from the later of the date the return was filed or the due date of the return.
tap to reveal
How do tax credits differ from tax deductions in terms of their impact on tax liability?
Tax credits directly reduce tax liability dollar-for-dollar, while deductions reduce taxable income, thus reducing tax liability indirectly based on the marginal tax rate.
tap to reveal
What is 'adjusted basis' in the context of property transactions?
The original cost basis of an asset adjusted for capital improvements, depreciation, and other events, used to determine gain or loss on sale.
tap to reveal
Explain the tax treatment of net Section 1231 gains and losses.
Net Section 1231 gains are treated as long-term capital gains, while net Section 1231 losses are treated as ordinary losses.
tap to reveal
What is the maximum deduction for State and Local Taxes (SALT) for individuals?
$10,000 per household.
tap to reveal
What is the tax treatment of alimony paid for divorce agreements executed after December 31, 2018?
Alimony paid is neither deductible by the payer nor includable in income by the recipient for agreements executed after December 31, 2018.
tap to reveal

Business Analysis and Reporting (BAR)

## Business Analysis and Reporting (BAR) Overview

The BAR section of the CPA Exam assesses a candidate's ability to apply analytical skills in financial management, data analytics, operations management, and enterprise risk management. It focuses on understanding how these areas contribute to business decision-making and performance.

## Financial Management

Financial Management involves optimizing an organization's financial resources to maximize shareholder wealth. Key topics include capital budgeting, which evaluates long-term investment projects. Techniques like Net Present Value (NPV), Internal Rate of Return (IRR), and Payback Period are used. NPV is generally preferred as it considers the time value of money and provides a direct measure of value creation. Understanding the Weighted Average Cost of Capital (WACC) is crucial, as it represents the average rate of return a company expects to pay to finance its assets. Working capital management focuses on efficiently managing current assets (cash, accounts receivable, inventory) and current liabilities (accounts payable) to ensure liquidity and profitability.

## Data Analytics

Data Analytics is the process of examining data to uncover insights and support decision-making. There are four main types:

  • Descriptive Analytics: What happened? (e.g., historical sales reports)
  • Diagnostic Analytics: Why did it happen? (e.g., root cause analysis of sales decline)
  • Predictive Analytics: What will happen? (e.g., sales forecasting, risk prediction)
  • Prescriptive Analytics: What should we do? (e.g., optimal pricing strategies, resource allocation)

Data visualization is essential for effectively communicating complex data insights. CPAs must also understand data governance, data quality, and the ethical considerations of data use.

## Operations Management

Operations Management deals with the design, operation, and improvement of the systems that create and deliver a company's primary products and services. Supply Chain Management (SCM) optimizes the flow of goods, services, and information from suppliers to customers. Concepts like Lean Manufacturing focus on eliminating waste (e.g., overproduction, waiting, defects) to improve efficiency and value. Six Sigma aims to reduce defects and variability in processes to achieve near-perfect quality. Other areas include capacity planning, forecasting, and total quality management (TQM).

## Enterprise Risk Management (ERM)

The COSO ERM Framework provides a comprehensive approach for organizations to manage risks that could affect their ability to achieve objectives. It emphasizes integrating risk management into strategy-setting and performance. Key components include governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting. CPAs play a role in identifying, assessing, and responding to risks, ensuring alignment with the organization's risk appetite.

  • NPV is generally preferred over IRR for capital budgeting, especially for mutually exclusive projects, as it directly measures value creation.
  • Working Capital = Current Assets - Current Liabilities, indicating short-term liquidity.
  • WACC represents the average cost of financing a company's assets through debt and equity.
  • The four types of data analytics are descriptive, diagnostic, predictive, and prescriptive.
  • Lean Manufacturing focuses on eliminating waste to improve efficiency and value.
  • Six Sigma aims to reduce defects and variability in processes to enhance quality.
  • The COSO ERM framework helps organizations manage risks to achieve strategic objectives.
  • Supply Chain Management (SCM) optimizes the flow of goods and information from origin to consumption.
What is the primary goal of capital budgeting?
To evaluate long-term investment projects to maximize shareholder wealth.
tap to reveal
Which type of data analytics answers the question 'Why did it happen?'
Diagnostic Analytics.
tap to reveal
Define WACC and its significance.
Weighted Average Cost of Capital; it's the average rate of return a company expects to pay to all its security holders to finance its assets.
tap to reveal
What is the main objective of Lean Manufacturing?
To eliminate waste (Muda) in all forms within a process to improve efficiency and deliver more value.
tap to reveal
According to the COSO ERM framework, what is 'risk appetite'?
The amount of risk, on a broad level, an organization is willing to accept in pursuit of value.
tap to reveal
What is the formula for calculating Net Present Value (NPV)?
NPV = Sum of (Cash Flow_t / (1 + r)^t) - Initial Investment, where 'r' is the discount rate (cost of capital).
tap to reveal
What is the difference between Predictive and Prescriptive Analytics?
Predictive analytics forecasts what will happen, while prescriptive analytics recommends what action should be taken.
tap to reveal