Cheat sheet

EPSO Auditors (AD7) Cheat Sheet

Competition Format

Not publishedof exam

Reasoning TestsField MCQEUFTEReserve ListScoring Logic

Audit Standards & Frameworks

Not publishedof exam

Standard-SettersISSAI PillarsIIA Standards 2024Core Distinctions

Risk, Materiality & Evidence

Not publishedof exam

Internal Control & Fraud

Not publishedof exam

COSO FrameworkSegregation of DutiesFraud TriangleManagement Override

IT Audit & Performance Audit

Not publishedof exam

IT ControlsData AnalyticsThree EsAudit Approaches

Reporting & EU Accountability

Not publishedof exam

Audit OpinionsECADAS & DischargeOLAF

Quick Facts

Competition
EPSO/AD/428/26
Grade
AD7
Reserve List
448 places
Field MCQ
30 Q, 40 min
Field MCQ Pass
15 of 30
Verbal Pass
10 of 20
EUFTE Pass
5 of 10
Fee
EUR 0
Retake
Apply once only
Applications
Closed 19 May 2026

Which Test Applies

  1. Testing text-based deduction→Verbal reasoning
  2. Testing tables and percentages→Numerical reasoning
  3. Testing figure pattern rules→Abstract reasoning
  4. Testing applied audit knowledge→Field-related MCQ
  5. Testing written EU communication→EUFTE essay

Test Stages

Verbal Reasoning
20 Q, 35 minPass 10/20
Numerical Reasoning
10 Q, 20 min
Abstract Reasoning
10 Q, 10 min
Num + Abstract Combined
Scored togetherPass 10/20
Field-Related MCQ
30 Q, 40 minPass 15/30, ranks
EUFTE Essay
40 min, writtenPass 5/10
Language 1
Reasoning tests language
Language 2
Field MCQ + EUFTE

Scoring Logic

Reasoning tests
Eliminatory, pass or fail
Field MCQ score
Ranks surviving candidates
EUFTE
Eliminatory, not ranked
Scoring order
Reasoning, then MCQ, EUFTE
EUFTE scored for
About 1.5x the places sought
Reserve list
448 places, alphabetical order
Retake this competition
Not allowed, apply once
Next attempt
Future EPSO competition only

Three Lines Model

1st owns, 2nd challenges, 3rd assures

1st: management2nd: risk + compliance3rd: internal audit

ISA vs ISSAI

ISA

  • IAASB standard-setter
  • Private financial-statement audits
  • Incorporated into ISSAI 2000s

ISSAI

  • INTOSAI standard-setter
  • Public-sector audit standards
  • Four fundamental pillars

Private root vs public pillars

Standard-Setters & Pillars

ISA
IAASB; financial-statement audits
ISSAI
INTOSAI; public-sector audits
IPPF
IIA; internal audit framework
IFAC
Parent body of IAASB
Lima Declaration
1977; SAI independence root
Mexico Declaration
2007; SAI independence pillars
ISSAI 100
Fundamental auditing principles
ISSAI 200
Financial audit principles
ISSAI 300
Performance audit principles
ISSAI 400
Compliance audit principles
ISSAI 2000s
Financial audit standards; embed ISAs

Internal vs External Audit

Internal Audit

  • Inside the organisation
  • Reports to own governance
  • Ongoing assurance and advice

External Audit

  • Outside the organisation
  • Reports to outside stakeholders
  • Periodic independent opinion

Neither substitutes the other

IIA Standards 2024

5 Domains
Purpose, Ethics, Govern, Manage, Perform
15 Principles
Grouped requirement themes
52 Standards
Must and should rules
Effective date
9 January 2025
Replaces
2017 IPPF edition
External quality review
Independent, at least 5-yearly

Core Distinctions

External audit
Outside body, outside stakeholders
Internal audit
Inside org, own governance
Three Lines Model
2020; replaces Three Lines Defense
First line
Management owns the risk
Second line
Risk and compliance challenge
Third line
Internal audit gives assurance
Professional scepticism
Question evidence, don't assume

Audit Risk Formula

Risk = Inherent x Control x Detection

Inherent: item's own riskControl: controls may miss itDetection: auditor's own risk

Inherent vs Control Risk

Inherent Risk

  • Exists before any controls
  • Driven by item's nature

Control Risk

  • Depends on control design
  • Needs control testing to lower

Item's nature vs control strength

Risk Component Picker

  1. Item is inherently complex→Inherent risk(Before controls)
  2. Controls might fail to catch it→Control risk
  3. Auditor sets how much testing→Detection risk
  4. Need total audit risk→Multiply all three
  5. No control testing was done→Assess control risk at maximum

Audit Risk Model

Audit risk
Inherent x control x detection
Inherent risk
Exists before any controls
Control risk
Controls fail to catch it
Detection risk
Auditor's own procedures miss it
Detection risk is
Set directly by the auditor

Materiality vs Performance Materiality

Materiality

  • Threshold for the statements
  • Influences user decisions

Performance Materiality

  • Set lower than materiality
  • Limits aggregate undetected error

Whole-statement line vs safety margin

Materiality

Materiality
Threshold influencing user decisions
Performance materiality
Set lower than materiality
ECA materiality
2% error-rate threshold
Materiality's role
Anchor, not a rigid cutoff

Evidence & Criteria

Sufficient evidence
Enough quantity for the risk
Appropriate evidence
Relevant and reliable
Most reliable evidence
Auditor-obtained or external source
Management assertions
Existence, completeness, accuracy, valuation
Audit criteria
Benchmarks for a performance audit
Inquiry alone
Must be corroborated further
Audit documentation
Enough for an unconnected reviewer

Fraud Triangle

Incentive + Opportunity + Rationalisation = fraud

Incentive: pressure to actOpportunity: weak controls allow itRationalisation: self-justifying mindset

Error vs Fraud

Error

  • Unintentional misstatement
  • No deception intended

Fraud

  • Intentional deception
  • Seeks unjust advantage

Intent is the dividing line

Control Timing Picker

  1. Check before payment approved→Ex-ante control
  2. Review after transaction done→Ex-post control
  3. Only ex-post controls exist→Errors caught after payment
  4. Testing if control was applied→Operating effectiveness
  5. Testing if control design works→Design effectiveness

COSO Framework

COSO
5 components, 17 principles
EU ICF
Mirrors COSO's five components
Segregation of duties
Split authorise, custody, record
Design effectiveness
Would the control work
Operating effectiveness
Did the control actually function
Ex-ante control
Checks before the transaction
Ex-post control
Reviews after the transaction
Control ownership
Management owns; audit evaluates

Fraud Risk

Fraud triangle
Incentive, opportunity, rationalisation
Management override
Presumed risk in every audit
Error vs fraud
Unintentional versus intentional deception
Revenue fraud presumption
Standards presume a revenue risk
Rebutting the presumption
Needs documented justification
Whistleblower channel
Bypasses the management chain

Three Es Mnemonic

Economy, Efficiency, Effectiveness: cost, output, outcome

Economy: resource costEfficiency: output per inputEffectiveness: objectives achieved

General vs Application IT Controls

General IT Controls

  • Cover whole IT environment
  • Access, change, operations

Application Controls

  • Built into one system
  • Automated validation checks

Environment-wide vs system-specific

Performance Audit Approach

  1. Ask if systems function properly→System-oriented approach
  2. Ask if objectives were achieved→Result-oriented approach
  3. Ask what caused a problem→Problem-oriented approach
  4. Need cost versus quality check→Economy
  5. Need output per input check→Efficiency
  6. Need objective achievement check→Effectiveness

IT Audit

General IT controls
Access, change, operations environment
Application controls
Built into one system
Logical access
Least privilege, reviewed regularly
Change management
Request, test, approve, document
Data analytics
Tests the full population
Cybersecurity scope
Confidentiality, integrity, availability

Performance Audit

Three Es
Economy, efficiency, effectiveness
System-oriented approach
Do the systems function properly
Result-oriented approach
Were the objectives achieved
Problem-oriented approach
What caused the deviation
Outputs
Goods or services produced
Outcomes
Broader results those outputs cause
Root-cause focus
Prevents the finding's recurrence

Opinion Ladder

Unmodified -> Qualified -> Adverse -> Disclaimer

Unmodified: cleanQualified: limited issueAdverse: pervasive issueDisclaimer: no opinion possible

DAS vs Discharge

DAS

  • ECA's annual audit opinion
  • Article 287 TFEU

Discharge

  • Parliament's political decision
  • Article 319 TFEU

Auditor opinion vs political decision

Audit Opinion Picker

  1. No material misstatement found→Unmodified opinion
  2. Material but not pervasive→Qualified opinion
  3. Material and pervasive→Adverse opinion
  4. Cannot get sufficient evidence→Disclaimer of opinion(Pervasive effect)
  5. Error rate above 2% EU threshold→Treat as material

Audit Reporting

Unmodified opinion
No material misstatement
Qualified opinion
Material, not pervasive
Adverse opinion
Material and pervasive
Disclaimer opinion
Cannot obtain enough evidence
Finding elements
Criteria, condition, cause, effect
Governance body
Oversees strategy, not operations
Recommendation follow-up
Tracks real implementation progress

Qualified vs Adverse Opinion

Qualified Opinion

  • Material but not pervasive
  • Still mostly reliable

Adverse Opinion

  • Material and pervasive
  • Not reliable overall

Contained issue vs pervasive issue

EU Accountability Bodies

ECA
EU's external auditor, Luxembourg
ECA Members
27, one per state
ECA term
Six years, renewable
DAS
Article 287 TFEU opinion
Discharge
Article 319 TFEU; Parliament decides
OLAF
Investigates fraud, doesn't prosecute
Financial Regulation
Regulation 2024/2509, a recast
Budget modes
Direct, indirect, shared management

Common Traps

Error vs fraud

Error is unintentional ≠ Fraud is intentional deception

Materiality vs performance materiality

Materiality covers whole statement ≠ Performance materiality sets testing threshold

Internal vs external audit

Internal reports to own board ≠ External reports to outsiders

Design vs operating effectiveness

Design asks if it would work ≠ Operating asks if it did work

Reasoning tests vs field MCQ

Reasoning tests are eliminatory ≠ Field MCQ ranks survivors

EUFTE vs field MCQ

EUFTE is pass or fail ≠ Field MCQ ranking builds the list

General vs application IT controls

General controls cover whole environment ≠ Application controls sit in one system

ECA vs OLAF

ECA audits EU spending ≠ OLAF investigates fraud, doesn't prosecute

Last Minute

  1. 1.Field MCQ: 30 Q, 40 min
  2. 2.Field MCQ needs 15 of 30
  3. 3.Verbal reasoning: 20 Q, 35 min
  4. 4.Verbal needs 10 of 20
  5. 5.Numerical, Abstract combined: 10 of 20
  6. 6.EUFTE needs 5 of 10
  7. 7.EUFTE is pass/fail, not ranked
  8. 8.Only Field MCQ score ranks candidates
  9. 9.Reserve list has 448 alphabetical names
  10. 10.No retake; apply again only later
  11. 11.Language 2 covers Field MCQ, EUFTE
  12. 12.ECA materiality threshold is 2 percent
  13. 13.Risk = inherent x control x detection
  14. 14.COSO has 5 components, 17 principles
Same family resources

Explore More EU & European Civil Service Exams

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.