1/12
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Reporting on Controls at a Service Organization
Services are considered part of a user entity's information system when they affect transaction initiation, execution, processing, or reporting; service auditors perform attestation engagements to report on controls relevant to financial reporting or security/confidentiality.
Objectives
Service auditors seek reasonable assurance regarding fair presentation of system description and suitable design of controls as of a date (Type 1) or throughout a period (Type 2), as well as operating effectiveness during a period (Type 2), and report findings.
Procedures
Service auditor procedures include assessing description suitability, obtaining understanding of the system, obtaining management's written assertion, evaluating design suitability, testing operating effectiveness (Type 2), assessing risks, and evaluating overall presentation.
SOC 1 Reports
focus on internal controls over financial reporting (ICFR).
SOC 2 Reports
evaluate controls related to security, availability, processing integrity, confidentiality, or privacy.
SOC 1 (SOC for Service Organizations: Internal Control Over Financial Reporting)
Reports specifically designated for service organization controls relevant to user entities' internal control over financial reporting.
SOC 2 (SOC for Service Organizations: Trust Services Criteria)
Reports addressing service organization controls relevant to security, availability, processing integrity, confidentiality, or privacy.
Type 1 and Type 2 Reports
Type 1 reports evaluate design and implementation as of a specific date, while Type 2 reports evaluate design, implementation, and operating effectiveness throughout a specified period.
Type 1 Report
Includes management's system description, a written assertion as of a specified date, and the auditor's opinion on description fairness and control design suitability.
Type 2 Report
Includes management's system description, a written assertion covering a specified period, and the auditor's opinion on description fairness, design suitability, and operating effectiveness, along with detailed test descriptions and results.
User Auditor Considerations
User auditors must understand the service organization's services and impact on internal control to assess risks and design responsive audit procedures.
User Auditor Responsibilities
User auditors use SOC 1 reports for risk assessment; Type 1 reports aid understanding but cannot reduce control risk below maximum, whereas Type 2 reports evaluate operating effectiveness and allow control risk reduction.
Reporting by the User Auditor
The user auditor must issue a qualified or disclaimer opinion if sufficient audit evidence is unobtainable; reference to the service auditor is prohibited in unmodified opinions but allowed to explain an opinion modification.