Free EPSO Auditors (AD7) Exam Flashcards

Memorize 50 essential terms and definitions for the EPSO Auditors Open Competition (AD7, field of Audit). See the term, recall the definition, then flip to check yourself.

50 Flashcards
9 Topics
100% Free
TermClick to flip

ISA (International Standards on Auditing)

Tap to reveal definition
Card 1 of 50Auditing Standards & Frameworks

Filter by Topic

Jump to Card

About These EPSO Auditors (AD7) Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the EPSO Auditors Open Competition (AD7, field of Audit). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

Auditing Standards & Frameworks6 cards
Audit Risk & Materiality6 cards
Evidence & Audit Criteria6 cards
Internal Control6 cards
Fraud Risk5 cards
IT Audit5 cards
Performance Audit5 cards
Reporting & Quality Assurance5 cards
EU Public-Sector Accountability6 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

ISA (International Standards on Auditing)

Issued by the independent International Auditing and Assurance Standards Board (IAASB) for financial-statement audits, covering risk assessment, evidence, and reporting. Public-sector financial audit uses them too: INTOSAI's financial-audit standards (ISSAI 2000–2899) incorporate the ISAs, so ISA concepts carry over to EU audit work.

ISSAI (International Standards of Supreme Audit Institutions)

Issued by INTOSAI under the INTOSAI Framework of Professional Pronouncements. Four fundamental-principle pillars: ISSAI 100 (general auditing principles), 200 (financial audit), 300 (performance audit), 400 (compliance audit) — built on the 1977 Lima Declaration and the 2007 Mexico Declaration on SAI independence.

IPPF (International Professional Practices Framework)

Issued by the IIA for internal audit functions. Its 2024 edition, effective since 9 January 2025, made the Global Internal Audit Standards (5 domains, 15 principles, 52 standards) the mandatory core, replacing the 2017 Standards. It governs internal audit, not external audit bodies.

Three Lines Model (IIA, 2020)

Updates the 2013 'Three Lines of Defense.' First line: management owns and manages risk day to day. Second line: risk, compliance, and quality functions give expertise and challenge. Third line: internal audit gives independent assurance to the governing body, which sits outside the numbered lines.

External audit vs. internal audit

External audit (e.g., the ECA or a national Supreme Audit Institution) is organisationally separate from the auditee and reports to outside stakeholders. Internal audit sits inside the organisation, reports to its own governing body or management, and provides ongoing assurance and advice. Neither substitutes for the other.

Professional scepticism

A questioning mindset that stays alert to conditions suggesting possible misstatement or fraud and critically assesses evidence rather than accepting management's explanations at face value. Required under ISA and ISSAI throughout the entire audit, not only during fraud-specific procedures.

Audit risk model

Audit risk = inherent risk x control risk x detection risk. Inherent and control risk together make up the risk of material misstatement, which exists independently of the audit; the auditor plans responses that reduce overall audit risk to an acceptably low level, never to zero.

Inherent risk

The susceptibility of an assertion to material misstatement before considering any related controls. It is driven by the nature of the item itself — complexity, judgement involved, susceptibility to fraud — not by how well the auditee's controls address it.

Control risk

The risk that a misstatement will not be prevented, or detected and corrected, on a timely basis by the auditee's internal control. The auditor can assess it below the maximum only by planning to test the controls; without control testing, the risk of material misstatement is assessed as equal to inherent risk.

Detection risk

The risk that the auditor's own procedures fail to detect a material misstatement that exists. Unlike inherent and control risk, the auditor sets detection risk directly by choosing how rigorous the audit procedures are, and it moves inversely with the other two risk components.

Materiality vs. performance materiality

Materiality is the threshold at which a misstatement could reasonably influence users' decisions on the financial statements as a whole. Performance materiality is set lower, to reduce the probability that undetected and uncorrected misstatements, added together, exceed materiality.

ECA's materiality threshold for legality/regularity

The European Court of Auditors applies a 2% materiality threshold to the estimated level of error in EU budget spending when forming its Statement of Assurance opinion. It also weighs qualitative factors, so 2% is a quantitative anchor rather than a rigid pass/fail cut-off.

Sufficient appropriate audit evidence

'Sufficient' addresses the quantity of evidence needed, driven by assessed risk and evidence quality; 'appropriate' addresses its relevance and reliability. Both conditions must be met together — a larger volume of low-quality evidence cannot substitute for reliable evidence.

Which audit evidence is generally most reliable?

Evidence obtained directly by the auditor (such as observation or recalculation) and evidence from independent external sources (such as confirmations) is generally more reliable than evidence obtained indirectly or supplied by the auditee. Evidence generated under effective internal controls is likewise more reliable than evidence from weak controls.

Management assertions (financial statement audit)

Representations embedded in the financial statements that the auditor tests, such as occurrence or existence, completeness, accuracy and valuation, cut-off, classification, rights and obligations, and presentation. Different procedures target different assertions; one test rarely covers them all.

Audit criteria in a performance audit

The benchmarks that actual performance is compared against, drawn from laws, standards, sound principles, or best practice. ISSAI 300 says criteria should be discussed with the auditee, but selecting suitable criteria is the auditor's responsibility; in complex audits they may be defined during the audit rather than in advance.

Why is a management inquiry alone insufficient audit evidence?

Inquiry helps the auditor understand the entity and identify risk, but because it comes from an interested party it must be corroborated by other procedures — inspection, observation, recalculation, external confirmation — before it can be relied on as sufficient evidence.

COSO Internal Control-Integrated Framework (2013)

Defines internal control through five components — control environment, risk assessment, control activities, information and communication, and monitoring activities — supported by 17 principles. All five components must be present, functioning, and operating together for control to be judged effective.

European Commission's Internal Control Framework (ICF)

Set out in Commission document C(2017) 2373 for Commission departments. It mirrors COSO's five components and 17 principles rather than inventing a separate EU-only model, so general COSO concepts transfer directly to this EU public-sector context.

Segregation of duties

Dividing authorisation, custody of assets, and record-keeping among different people so no single person can both commit and conceal an error or fraud. It is one control activity within COSO's framework, not a stand-alone control model, and must be assessed alongside the other components.

Control design effectiveness vs. operating effectiveness

Design effectiveness asks whether a control, if operated as prescribed, would prevent or detect a misstatement. Operating effectiveness asks whether the control actually functioned consistently throughout the period. A well-designed control that is not applied consistently is not an effective control.

Ex-ante control vs. ex-post control

Ex-ante controls check a transaction before it is authorised or paid, such as verifying supporting documents before payment. Ex-post controls review transactions after completion, such as sample re-checks or audits. Relying only on ex-post controls lets an error or irregularity reach completion before it is caught.

Who 'owns' internal control in an organisation?

Management designs, operates, and owns internal controls. Internal audit evaluates them and may advise, but it should not take on management responsibilities such as implementing controls, because later auditing its own work would impair its objectivity.

Fraud triangle

Three conditions usually present when fraud occurs: incentive/pressure (a reason to commit fraud), opportunity (a perceived ability to carry it out, often from weak controls), and rationalisation/attitude (a mindset that justifies the act). Removing any one factor reduces fraud risk.

Why is management override of controls treated as an ever-present fraud risk?

Management can often use its position to override controls that otherwise operate effectively, such as posting unusual journal entries or bypassing approvals. Auditing standards treat this as a risk present in every audit, regardless of what the entity-specific risk assessment otherwise suggests.

Error vs. fraud

An error is an unintentional misstatement; fraud is an intentional act involving deception to obtain an unjust or illegal advantage. The auditor's objective is reasonable assurance that the financial statements are free of material misstatement from either cause — not a guarantee that fraud will be detected.

Why do auditors presume a fraud risk in revenue recognition?

Revenue is a common target for manipulation, used to meet targets or mask problems, so auditing standards direct auditors to presume a fraud risk related to revenue recognition. The presumption can be rebutted only when specific circumstances justify it, and the auditor must then document why.

Why do audit and anti-fraud frameworks require independent reporting channels?

A channel that bypasses the normal management chain, such as to an audit committee or a body like OLAF, protects whistle-blowers and ensures suspected fraud involving management itself can still surface and be investigated, rather than being suppressed at the point it occurred.

General IT controls vs. application controls

General IT controls operate across the whole IT environment — access security, change management, IT operations — and support the reliable running of all systems. Application controls are built into one specific system or process, such as automated validation checks. Weak general controls can undermine otherwise strong application controls.

Logical access controls

Controls restricting who can read, change, or execute data and programmes, using user IDs, role-based permissions, and periodic access reviews. The goal is least-privilege access: each user holds only the access their role needs, reviewed regularly rather than granted once and left unchanged.

IT change management controls

Controls ensuring changes to systems or programmes are requested, tested, approved, and documented before being moved into the live production environment, so uncontrolled or unauthorised changes cannot silently alter processing logic or data.

Why do modern audits increasingly use data analytics?

Analysing a full population of transactions, rather than a small manual sample, lets auditors identify anomalies, outliers, and control exceptions across all of the data, improving the chance of detecting a misstatement that a traditional sample might miss entirely.

Why does cybersecurity sit inside an IT audit's scope?

A security breach can compromise the confidentiality, integrity, or availability of the financial and operational data underlying the accounts. Auditors assess cybersecurity controls, such as access management and incident response, as part of judging whether IT-dependent processes can be relied on.

The three Es of performance audit

Economy (minimising the cost of resources used while maintaining quality), efficiency (the relationship between resources used and outputs produced), and effectiveness (the extent to which objectives are achieved and intended results obtained). A performance audit can examine any or all three.

Three approaches to performance (value-for-money) audit under ISSAI 300

System-oriented (do management systems, such as financial management, function properly?), result-oriented (were output or outcome objectives achieved as intended?), and problem-oriented (what causes a known problem or deviation from criteria?). Auditors may combine them; the choice shapes the audit questions and evidence.

How does a performance audit differ from a financial audit?

A financial audit expresses an opinion on whether accounts are reliable. A performance audit instead reaches conclusions and makes recommendations on economy, efficiency, and effectiveness, and typically does not issue a pass/fail opinion in the same binary sense as a financial audit.

Outputs vs. outcomes in performance audit

Outputs are the goods or services a programme directly produces, such as the number of inspections completed. Outcomes are the broader results those outputs are meant to cause, such as improved compliance. A programme can deliver its outputs on time while still failing to achieve its intended outcomes.

Why do audit recommendations target root causes rather than symptoms?

A recommendation that fixes only the immediately observed problem, without addressing why it happened, tends to let the same finding recur in a later audit. Identifying the underlying root cause supports a recommendation actually capable of preventing recurrence.

Types of audit opinion

Unmodified/unqualified (no material misstatement), qualified (a material but not pervasive misstatement or evidence limitation), adverse (material and pervasive misstatement), and disclaimer of opinion (the auditor cannot obtain sufficient appropriate evidence and the possible effects could be both material and pervasive).

'Those charged with governance'

The person(s) or body (such as an audit committee or board) responsible for overseeing an entity's strategic direction and accountability — distinct from management, who run day-to-day operations. Auditors are required to communicate certain matters specifically to this group.

The standard elements of an audit finding

Criteria (what should be), condition (what actually is), cause (why the gap exists), and effect/consequence (why it matters). Omitting cause or effect weakens a finding's persuasiveness and makes any resulting recommendation harder to justify.

Why do auditors track the implementation of their recommendations?

Issuing a recommendation does not guarantee it is implemented. Follow-up work, tracking status against agreed action plans and deadlines, confirms whether management actually addressed the finding, closing the loop between reporting and real improvement.

External quality assessment of an audit function

Under the Global Internal Audit Standards (Standard 8.4), a qualified, independent assessor or team must review an internal audit function's conformance at least once every five years. A self-assessment counts only when it is independently validated; self-assessment alone is not enough.

European Court of Auditors (ECA)

The EU's external auditor, established by the 1975 Budgetary Treaty and operational since 1977, based in Luxembourg. One Member is appointed per EU country (27 Members total) for a renewable six-year term by the Council, after consulting Parliament.

Statement of Assurance (DAS)

Under Article 287 TFEU, the ECA's annual opinion covers two separate questions: the reliability of the EU's accounts, and the legality and regularity of the revenue and expenditure underlying them. The two questions can receive different opinions in the same year.

EU budget discharge procedure

Under Article 319 TFEU, the European Parliament, acting on a recommendation from the Council, decides whether to grant discharge to the Commission for its implementation of a given year's EU budget, taking into account the ECA's Annual Report. Discharge can be granted, postponed, or refused.

OLAF (European Anti-Fraud Office)

Investigates fraud, corruption, and other illegal activity affecting the EU budget, plus serious misconduct by EU staff. OLAF is an administrative investigator, not a prosecutor: it refers cases for criminal prosecution to national authorities or, where applicable, the EPPO.

How much audit documentation is enough?

Enough for an experienced auditor with no previous connection to the audit to understand the nature, timing, and extent of procedures performed, the evidence obtained and results, and the significant matters, judgements, and conclusions (ISA 230). Work that is not documented is hard to defend in review or quality assurance.

The EU's Financial Regulation

The core rulebook for establishing and implementing the general EU budget and for presenting and auditing its accounts. Regulation (EU, Euratom) 2024/2509, a recast applicable from 30 September 2024, currently governs it, having replaced the earlier Regulation 2018/1046 rather than merely amending it.

How is the EU budget implemented?

Mainly through three modes: direct management (by Commission departments, EU delegations, or executive agencies), indirect management (entrusted to partners such as international organisations, third countries, or the EIB Group), and shared management with Member States, used heavily for agriculture and cohesion spending. The mode affects who performs first-level checks.

Frequently Asked Questions

What is the EPSO Auditors (AD7) competition and how is it structured?

EPSO/AD/428/26 is an open competition to build a reserve list of 448 Administrators (AD7) in the field of audit. Candidates sit reasoning tests (verbal, numerical, abstract), a 30-question field-related MCQ, and a free-text essay on EU matters (EUFTE); missing any pass mark ends a candidate's participation. EPSO held the tests on 30 September 2026, so check the notice of any later Auditors competition for changes.

What does the field-related MCQ test cover?

EPSO's notice of competition publishes only the overall format (30 questions, 40 minutes, pass mark 15/30) and not a sub-topic weighting. Based on the audit duties listed in the notice, expect coverage spread across auditing standards, risk and materiality, evidence, internal control, fraud risk, IT audit, performance audit, reporting, and EU public-sector accountability rather than concentrated in one area.

Is there a separate EU-knowledge test, and does the EUFTE essay count toward ranking?

No stand-alone EU-knowledge MCQ exists in this competition. The EUFTE is a 40-minute written test in language 2 (pass mark 5/10) that assesses written communication using EU-matters documentation published in advance; it is neither a language test nor a factual-knowledge test. Only the field-related MCQ score ranks candidates, and the EUFTE is marked only for the top-ranked candidates and only against its pass mark.

What happens if I don't pass or I'm not placed on the reserve list?

There is no fixed retake wait. A candidate may apply to the same competition only once, so EPSO offers no retake within this competition; a candidate who fails a stage or is not selected can try again only when EPSO opens a new Auditors or other relevant competition, and there is no fixed cycle for when that happens.

Are these flashcards official EPSO or EU material?

No. These are independent study flashcards by OpenExamPrep covering field-related audit concepts, such as ISA, ISSAI, COSO, and EU accountability bodies, that are relevant to EPSO/AD/428/26. They are not produced, reviewed, or endorsed by EPSO or any EU institution.

Same family resources

Explore More EU & European Civil Service Exams

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.