| Course | D251 Advanced Auditing |
|---|---|
| Task | Task 1 |
| Paper type | Revenue cycle audit risk assessment and procedures |
| Length | About 1,200 words, 3 pages |
| Format | APA 7 |
| School | Western Governors University (WGU) |
| Program | MS Accounting |
| Updated | September 2026 |
Free sample paper for D251 Task 1
A December Too Good to Be True: Assessing Risk and Designing Procedures for the Revenue Cycle Audit of a Composite Medical Supply Distributor
Student Name
School of Business, Western Governors University
D251: Advanced Auditing, Task 1
Course Instructor
Month Day, Year
A December Too Good to Be True: Assessing Risk and Designing Procedures for the Revenue Cycle Audit of a Composite Medical Supply Distributor
The Client and the Engagement
Cascade Clinical Supply, a composite publicly traded distributor, sells medical and surgical supplies to about 2,400 clinics, surgery centers and small hospitals in the Pacific Northwest. Net sales for the year ended December 31 were $312 million, and pretax income was $24 million. The firm has audited Cascade for four years. Overall materiality for this year is set at $1.2 million, about 5% of pretax income, with performance materiality of $840,000.
Three facts from planning shape the revenue cycle audit. Fourth-quarter sales rose 28% over the prior year's fourth quarter, while sales for the first three quarters rose 6%. In January, Cascade introduced a new bonus plan paying sales representatives 2% of sales invoiced by December 31 above their annual targets. And credit memos issued in the first three weeks of January totaled $3.1 million, compared with $0.9 million a year earlier.
Engagement Risk
Engagement risk is the risk that the firm suffers loss or damage to its reputation from its association with the client, even if the audit report is correct. It is elevated here. Cascade is publicly traded, has a covenant in its credit agreement requiring a minimum ratio of earnings to interest, and missed analysts' revenue expectations in two of the last four quarters. Management therefore has reasons to present strong year-end results. Engagement risk does not change the audit risk model directly, but it leads the firm to set a lower acceptable audit risk and to assign more experienced staff to revenue.
Inherent Risk
PCAOB standards require the auditor to presume a fraud risk involving improper revenue recognition and to evaluate which types of revenue, transactions or assertions could give rise to it (Public Company Accounting Oversight Board [PCAOB], 2010). Research supports this focus: in a large study of firms subject to SEC enforcement for misstating their financial statements, revenue was the most frequently misstated account (Dechow et al., 2011).
At Cascade, the inherent risk is high for occurrence and cutoff. The bonus plan pays representatives for shipments invoiced before year-end, giving them a reason to ship early, ship goods customers did not order or record bill-and-hold sales that do not meet the criteria for transferring control. The surge in January credit memos is consistent with goods shipped in December and returned or canceled soon after. Inherent risk is also elevated for valuation of receivables, because several surgery center customers slowed payments during the year. Inherent risk for completeness is assessed as low: management's incentives favor overstating, not understating, sales.
Control Risk
Cascade's revenue cycle controls were tested last year and found to be designed and operating effectively. This year, walkthroughs found two changes. Sales representatives can now enter orders directly into the system from a mobile application, and orders under $25,000 no longer require a customer service review before shipment. In addition, the shipping manager can override the date on the bill of lading when shipments are staged but not picked up. These changes weaken the controls that previously prevented unauthorized orders and misdated shipments. Control risk for occurrence and cutoff is therefore assessed as moderate to high, pending tests of controls. Controls over credit approval and cash receipts are unchanged, and control risk for valuation is assessed as moderate.
The Audit Risk Model and Detection Risk
Audit risk is the risk that the auditor issues an unmodified opinion on financial statements that are materially misstated. It is a function of the risk of material misstatement, the combination of inherent and control risk, and detection risk, the risk that the auditor's procedures fail to detect a misstatement that exists (Arens et al., 2020). The auditor controls only detection risk. When the assessed risk of material misstatement is high, the auditor must accept a lower detection risk to keep audit risk acceptably low, which means more persuasive evidence from substantive procedures: more procedures, performed closer to year-end, on larger samples.
For Cascade, occurrence and cutoff have high inherent risk and moderate to high control risk, so acceptable detection risk is low. Valuation has elevated inherent risk and moderate control risk, so detection risk is set at moderate. Completeness carries low inherent risk, so detection risk can be higher, and standard analytical procedures will suffice.
Tests of Controls
Order authorization: select 40 orders entered through the mobile application in the fourth quarter and inspect evidence that the customer placed each order, such as a purchase order or email, since customer service review no longer applies to smaller orders.
Shipping date overrides: obtain the system log of all bill of lading date changes in December and January and inspect each for approval and supporting carrier records.
Credit approval: reperform credit limit checks for 25 orders from customers with past-due balances.
Substantive Procedures by Assertion
Cutoff: examine all shipments over $50,000 and a sample of smaller shipments recorded in the last ten business days of December and the first ten of January, comparing invoice dates with carrier pickup records and signed delivery receipts to confirm that control passed in the period recorded.
Occurrence: send positive confirmations to the 30 customers with the largest December sales and a random sample of 40 others, asking them to confirm balances and the terms of December orders, including any side agreements allowing returns. Follow up nonresponses by examining subsequent cash receipts and shipping documents.
Bill-and-hold: identify every December sale where goods remained in Cascade's warehouse, and test whether each meets the criteria for revenue, including a substantive reason for the arrangement requested by the customer and goods identified separately and ready for shipment.
January credit memos: examine all credit memos over $25,000 issued through the date of the report, determine whether each relates to a December sale and evaluate whether the original sale should be reversed or a returns allowance increased.
Analytical procedures: compare December sales by representative with prior months and prior years, and investigate representatives whose December sales exceed their monthly average by more than 50%.
Valuation: test the aging of receivables, evaluate collectability of past-due surgery center balances using subsequent receipts and assess the adequacy of the allowance for doubtful accounts and the returns reserve.
Communication and Documentation
Because the bonus plan and control changes create a fraud risk, the engagement partner will discuss them with the audit committee early in fieldwork. Any misstatements found will be accumulated and evaluated for their effect on the opinion, and the weakened order authorization and shipping controls will be communicated in writing as control deficiencies, with an assessment of whether they rise to a material weakness.
Conclusion
Cascade's December is unusually strong at the same time that representatives are paid for December invoices and controls over orders and shipping dates have weakened. These facts raise the risk that fourth-quarter revenue includes sales that did not occur or belong in January. Setting detection risk low for occurrence and cutoff, and directing confirmations, cutoff tests and credit memo reviews at the specific risks, gives the audit the best chance of detecting a material misstatement if one exists.
References
Arens, A. A., Elder, R. J., Beasley, M. S., & Hogan, C. E. (2020). Auditing and assurance services (17th ed.). Pearson.
Dechow, P. M., Ge, W., Larson, C. R., & Sloan, R. G. (2011). Predicting material accounting misstatements. Contemporary Accounting Research, 28(1), 17-82. https://doi.org/10.1111/j.1911-3846.2010.01041.x
Public Company Accounting Oversight Board. (2010). AS 2110: Identifying and assessing risks of material misstatement. https://pcaobus.org/oversight/standards/auditing-standards/details/AS2110
What the D251 Task 1 instructions ask
The first D251 task asks you to plan the audit of a significant cycle for a client. You will usually describe the client and engagement, assess engagement, inherent and control risk, apply the audit risk model to set detection risk, design tests of controls and plan substantive procedures linked to assertions. The case may be supplied by your course. Evaluators expect risks drawn from the facts, such as a bonus plan paid on December invoices, standards cited accurately, procedures that address specific assertions and sample sizes or selection methods that make sense. A list of generic audit procedures, without links to the risks identified, will not meet the planning aspects. Reading the case twice and marking every fact that affects risk is the best preparation.
How this D251 Task 1 example is built
The paper opens with the client, its industry and why the engagement is higher risk this year. Each type of risk has its own section with the facts that raise or lower it. The audit risk model section explains how high inherent and control risk require low detection risk, and what that means for the nature, timing and extent of testing. Tests of controls are listed by control, each with a sample and the evidence to be inspected. Substantive procedures are organized by assertion, such as cutoff, occurrence and valuation. A communication section explains what the partner will discuss with the audit committee. The conclusion ties the unusually strong December to the incentives and control changes.
Where the D251 Task 1 rubric puts the marks
D251 Task 1 aspects are scored competent, approaching competence or not evident. A risk assessment aspect asks for engagement, inherent and control risk supported by facts. An audit risk model aspect rewards correct use of the model to set detection risk. A controls testing aspect looks for tests linked to key controls. A substantive procedures aspect wants procedures tied to assertions. A standards aspect asks for accurate references to auditing standards. Evaluators notice when procedures respond to specific risks, such as extending cutoff testing because of the bonus plan, and they expect PCAOB and AICPA standards to be cited correctly for a public company audit. Clear headings for each risk and each assertion make the plan easy to review.
D251 Task 1 help: what sends it back
D251 plans are weakest when procedures do not answer the risks. For each risk, name the procedure that addresses it. Standards are sometimes mixed, citing private company standards for a public company, so check which apply. Assertions may be missing, which makes procedures hard to evaluate; label each procedure with its assertion. Sample sizes can be arbitrary, so explain the selection method. Last, include communication with the audit committee where fraud risk is elevated, since standards require it and evaluators look for it. Explain how the results of tests of controls will change substantive testing if controls fail, since audit plans must adapt. Document your reasoning for each risk level, because reviewers and inspectors look for that link between assessment and response.
Get a D251 Task 1 example written to your instructions
Send the task instructions and rubric aspects from your D251 course of study. We write a custom revenue cycle audit to those exact aspects, returned in 24-48h. The first custom sample is free.
Other MBA sample papers
- D263 Task 1 Problem and Opportunity Analysis
- D375 Task 2 Brand Story and Video Script
- D379 Task 1 Social Media Strategy
- E200 Task 1 Inclusion-focused HR Approach
D251 Task 1 questions, answered
Which standards apply in D251 Task 1?
For a publicly traded client, PCAOB auditing standards govern. The sample cites the requirement to presume a fraud risk in revenue recognition and to assess risk by assertion.
What is the audit risk model in D251?
Audit risk equals the risk of material misstatement, made up of inherent and control risk, combined with detection risk. Higher assessed risk requires lower detection risk and more evidence.
Is the D251 client real?
No. Cascade Clinical Supply and its figures are invented for the sample. The auditing standards and requirements described are real. Use your course's client case. Every risk should come from its facts.
Why test cutoff in the D251 sample?
Because sales representatives are paid bonuses on December invoices and shipping date controls weakened, creating an incentive and an opportunity to record January sales in December. The procedure answers a specific risk.
Where can I find a free D251 Task 1 sample paper?
The Cascade revenue cycle audit plan sits above with notes on each risk. Send the client case your D251 task provides, and your first custom audit plan is written free.