Assurance Reports on Controls At a Service Organisation
(a)
To report only on whether controls at a service organization operated as described, or
(b)
To report only on controls at a service organization other than those related to a service that is likely to be relevant to user entities’ internal control as it relates to financial reporting (for example, controls that affect user entities’ production or quality control). (Ref: Para. A2)
(a)
A report on a user entity’s transactions or balances maintained by a service organization; or
(b)
An agreed-upon procedures report on controls at a service organization.
(a)
To obtain reasonable assurance about whether, in all material respects, based on suitable criteria:
(i)
(ii)
(iii)
(b)
To report on the matters in (a) above in accordance with the service auditor’s findings.
(a)
Carve-out method – Method of dealing with the services provided by a subservice organization, whereby the service organization’s description of its system includes the nature of the services provided by a subservice organization, but that subservice organization’s relevant control objectives and related controls are excluded from the service organization’s description of its system and from the scope of the service auditor’s engagement. The service organization’s description of its system and the scope of the service auditor’s engagement include controls at the service organization to monitor the effectiveness of controls at the subservice organization, which may include the service organization’s review of an assurance report on controls at the subservice organization.
(b)
(c)
Control objective – The aim or purpose of a particular aspect of controls. Control objectives relate to risks that controls seek to mitigate.
(d)
Controls at the service organization – Controls over the achievement of a control objective that is covered by the service auditor’s assurance report. (Ref: Para. A3)
(e)
(f)
Criteria – Benchmarks used to evaluate or measure a subject matter including, where relevant, benchmarks for presentation and disclosure.
(g)
Inclusive method – Method of dealing with the services provided by a subservice organization, whereby the service organization’s description of its system includes the nature of the services provided by a subservice organization, and that subservice organization’s relevant control objectives and related controls are included in the service organization’s description of its system and in the scope of the service auditor’s engagement. (Ref: Para. A4)
(h)
Internal audit function – An appraisal activity established or provided as a service to the service organization. Its functions include, amongst other things, examining, evaluating and monitoring the adequacy and effectiveness of internal control.
(i)
Internal auditors – Those individuals who perform the activities of the internal audit function. Internal auditors may belong to an internal audit department or equivalent function.
(j)
Report on the description and design of controls at a service organization (referred to in this SAE as a “type 1 report”) – A report that comprises:
(i)
The service organization’s description of its system;
(ii)
(iii)
(k)
(i)
The service organization’s description of its system;
(ii)
(iii)
A service auditor’s assurance report that: a.
(ii)
a.-c. above; and b.
(l)
Service auditor – A professional accountant in public practice who, at the request of the service organization, provides an assurance report on controls at a service organization.
(m)
Service organization – A third-party organization (or segment of a third-party organization) that provides services to user entities that are likely to be relevant to user entities’ internal control as it relates to financial reporting.
(n)
(o)
(p)
(q)
Test of controls – A procedure designed to evaluate the operating effectiveness of controls in achieving the control objectives stated in the service organization’s description of its system.
(r)
User auditor – An auditor who audits and reports on the financial statements of a user entity6.
(s)
User entity – An entity that uses a service organization.
(a)
Determine whether:
(i)
(ii)
The criteria to be applied by the service organization to prepare the description of its system will be suitable and available to user entities and their auditors; and
(iii)
The scope of the engagement and the service organization’s description of its system will not be so limited that they are unlikely to be useful to user entities and their auditors. 6 In the case of a subservice organization, the service auditor of a service organization that uses the services of the subservice organization is also a user auditor.
(b)
Obtain the agreement of the service organization that it acknowledges and understands its responsibility:
(i)
(ii)
(iii)
For stating in the service organization’s assertion the criteria it used to prepare the description of its system;
(iv)
For stating in the description of its system: a.
(v)
For identifying the risks that threaten achievement of the control objectives stated in the description of its system, and designing and implementing controls to provide reasonable assurance that those risks will not prevent achievement of the control objectives stated in the description of its system, and therefore that the stated control objectives will be achieved; and (Ref: Para. A10)
(vi)
To provide the service auditor with: a.
(a)
Whether the description presents how the service organization’s system was designed and implemented, including, as appropriate:
(i)
(ii)
(iii)
The related records and supporting information, including, as appropriate, accounting records, supporting information and specific accounts that are used to initiate, record, process and report transactions; this includes the correction of incorrect information and how information is transferred to the reports and other information prepared for user entities;
(iv)
How the service organization’s system deals with significant events and conditions, other than transactions;
(v)
The process used to prepare reports and other information for user entities;
(vi)
The specified control objectives and controls designed to achieve those objectives;
(vii)
Complementary user entity controls contemplated in the design of the controls; and 7 Framework for Assurance Engagements, paragraphs 33-36.
(viii)
Other aspects of the service organization’s control environment, risk assessment process, information system (including the related business processes) and communication, control activities and monitoring controls that are relevant to the services provided.
(b)
In the case of a type 2 report, whether the description includes relevant details of changes to the service organization’s system during the period covered by the description.
(c)
Whether the description omits or distorts information relevant to the scope of the service organization’s system being described, while acknowledging that the description is prepared to meet the common needs of a broad range of user entities and their auditors and may not, therefore, include every aspect of the service organization’s system that each individual user entity and its auditor may consider important in its particular environment.
(a)
The service organization has identified the risks that threaten achievement of the control objectives stated in the description of its system; and
(b)
The controls identified in that description would, if operated as described, provide reasonable assurance that those risks do not prevent the stated control objectives from being achieved.
(a)
Control objectives stated in the service organization’s description of its system are reasonable in the circumstances; (Ref: Para. A23)
(b)
Controls identified in that description were implemented;
(c)
Complementary user entity controls, if any, are adequately described; and
(d)
Services performed by a subservice organization, if any, are adequately described, including whether the inclusive method or the carve-out method has been used in relation to them.
(a)
Identifying the risks that threaten the achievement of the control objectives stated in the service organization’s description of its system; and
(b)
Evaluating the linkage of controls identified in the service organization’s description of its system with those risks.
(a)
Perform other procedures in combination with inquiry to obtain evidence about:
(i)
How the control was applied;
(ii)
(iii)
By whom or by what means the control was applied;
(b)
Determine whether controls to be tested depend upon other controls (indirect controls) and, if so, whether it is necessary to obtain evidence supporting the operating effectiveness of those indirect controls; and (Ref:
(c)
Determine means of selecting items for testing that are effective in meeting the objectives of the procedure. (Ref: Para. A35-A36)
(a)
Consider the purpose of the procedure and the characteristics of the population from which the sample will be drawn when designing the sample;
(b)
Determine a sample size sufficient to reduce sampling risk to an appropriately low level;
(c)
Select items for the sample in such a way that each sampling unit in the population has a chance of selection;
(d)
If a designed procedure is not applicable to a selected item, perform the procedure on a replacement item; and
(e)
If unable to apply the designed procedures, or suitable alternative procedures, to a selected item, treat that item as a deviation.
(a)
Identified deviations are within the expected rate of deviation and are acceptable; therefore, the testing that has been performed provides an appropriate basis for concluding that the control is operating effectively throughout the specified period;
(b)
Additional testing of the control or of other controls is necessary to reach a conclusion on whether the controls relative to a particular control objective are operating effectively throughout the specified period; or (Ref: Para.
(c)
The testing that has been performed provides an appropriate basis for concluding that the control did not operate effectively throughout the specified period.
(a)
Whether the work of the internal auditors is likely to be adequate for purposes of the engagement; and
(b)
If so, the planned effect of the work of the internal auditors on the nature, timing or extent of the service auditor’s procedures.
(a)
The objectivity of the internal audit function;
(b)
The technical competence of the internal auditors;
(c)
Whether the work of the internal auditors is likely to be carried out with due professional care; and
(d)
Whether there is likely to be effective communication between the internal auditors and the service auditor.
(a)
The nature and scope of specific work performed, or to be performed, by the internal auditors;
(b)
The significance of that work to the service auditor’s conclusions; and
(c)
The degree of subjectivity involved in the evaluation of the evidence gathered in support of those conclusions.
(a)
The work was performed by internal auditors having adequate technical training and proficiency;
(b)
The work was properly supervised, reviewed and documented;
(c)
Adequate evidence has been obtained to enable the internal auditors to draw reasonable conclusions;
(d)
Conclusions reached are appropriate in the circumstances and any reports prepared by the internal auditors are consistent with the results of the work performed; and
(e)
Exceptions relevant to the engagement or unusual matters disclosed by the internal auditors are properly resolved.
(a)
That reaffirm the assertion accompanying the description of the system;
(b)
That it has provided the service auditor with all relevant information and access agreed to; 9 and
(c)
That it has disclosed to the service auditor any of the following of which it is aware:
(i)
(ii)
Design deficiencies in controls;
(iii)
Instances where controls have not operated as described; and
(iv)
Any events subsequent to the period covered by the service organization’s description of its system up to the date of the service auditor’s assurance report that could have a significant effect on the service auditor’s assurance report.
(a)
The nature, timing, and extent of the procedures performed to comply with this SAE and applicable legal and regulatory requirements;
(b)
The results of the procedures performed, and the evidence obtained; and
(c)
Significant matters arising during the engagement, and the conclusions reached thereon and significant professional judgments made in reaching those conclusions.
(a)
The identifying characteristics of the specific items or matters being tested;
(b)
Who performed the work and the date such work was completed; and
(c)
Who reviewed the work performed and the date and extent of such review.
(a)
The specific reasons for making them; and
(b)
When and by whom they were made and reviewed.
(a)
A title that clearly indicates the report is an independent service auditor’s assurance report.
(b)
An addressee. 10 Standard on Quality Control (SQC) 1, paragraphs 74-76, provide further guidance.
(c)
Identification of:
(i)
(ii)
Those parts of the service organization’s description of its system, if any, that are not covered by the service auditor’s opinion.
(iii)
If the description refers to the need for complementary user entity controls, a statement that the service auditor has not evaluated the suitability of design or operating effectiveness of complementary user entity controls, and that the control objectives stated in the service organization’s description of its system can be achieved only if complementary user entity controls are suitably designed or operating effectively, along with the controls at the service organization.
(iv)
If services are performed by a subservice organization, the nature of activities performed by the subservice organization as described in the service organization’s description of its system and whether the inclusive method or the carve-out method has been used in relation to them. Where the carve-out method has been used, a statement that the service organization’s description of its system excludes the control objectives and related controls at relevant subservice organizations, and that the service auditor’s procedures do not extend to controls at the subservice organization. Where the inclusive method has been used, a statement that the service organization’s description of its system includes control objectives and related controls at the subservice organization, and that the service auditor’s procedures extended to controls at the subservice organization.
(d)
Identification of the criteria, and the party specifying the control objectives.
(e)
A statement that the report and, in the case of a type 2 report, the description of tests of controls are intended only for user entities and their auditors, who have a sufficient understanding to consider it, along with other information including information about controls operated by user entities themselves, when assessing the risks of material misstatements of user entities’ financial statements. (Ref: Para. A48)
(f)
A statement that the service organization is responsible for:
(i)
(ii)
(iii)
Stating the control objectives (where not identified by law or regulation, or another party, for example, a user group or a professional body); and
(iv)
Designing and implementing controls to achieve the control objectives stated in the service organization’s description of its system.
(g)
A statement that the service auditor’s responsibility is to express an opinion on the service organization’s description, on the design of controls related to the control objectives stated in that description and, in the case of a type 2 report, on the operating effectiveness of those controls, based on the service auditor’s procedures.
(h)
A statement that the engagement was performed in accordance with SAE 3402, “Assurance Reports on Controls at a Service Organization,” which requires that the service auditor comply with ethical requirements and plan and perform procedures to obtain reasonable assurance about whether, in all material respects, the service organization’s description of its system is fairly presented and the controls are suitably designed and, in the case of a type 2 report, are operating effectively.
(i)
(j)
A statement of the limitations of controls and, in the case of a type 2 report, of the risk of projecting to future periods any evaluation of the operating effectiveness of controls.
(k)
The service auditor’s opinion, expressed in the positive form, on whether, in all material respects, based on suitable criteria:
(i)
In the case of a type 2 report: a.
(ii)
In the case of a type 1 report: a.
(l)
The date of the service auditor’s assurance report, which shall be no earlier than the date on which the service auditor has obtained sufficient appropriate evidence on which to base the opinion.
(m)
Practitioner’s Signature-The report should be signed by the practitioner in his personal name. Where the firm is appointed, the report should be signed in the personal name of the engagement partner and in the name of the firm. The partner/proprietor signing the assurance report also needs to mention the membership number assigned by the Institute of
(n)
The place of signature – the report should name specific location, which is ordinarily the city where the report is signed.
(a)
The service organization’s description does not fairly present, in all material respects, the system as designed and implemented;
(b)
The controls related to the control objectives stated in the description were not suitably designed, in all material respects;
(c)
In the case of a type 2 report, the controls tested, which were those necessary to provide reasonable assurance that the control objectives stated in the service organization’s description of its system were achieved, did not operate effectively, in all material respects; or
(d)
The service auditor is unable to obtain sufficient appropriate evidence, the service auditor’s opinion shall be modified, and the service auditor’s assurance report shall contain a clear description of all the reasons for the modification.
(a)
presents how the service organization’s system was designed and implemented
(c)
does not omit or distort information relevant to the scope of the service organization’s system being described, while acknowledging that the description is prepared to meet the common needs of a broad range of user entities and may not, therefore, include every aspect of the service organization’s system that each individual user entity may consider important in its own particular environment.
(b)
the controls identified in that description would, if operated as described, provide reasonable assurance that those risks do not prevent the stated control objectives from being achieved; and
(a)
Selecting all items (100% examination). This may be appropriate for testing controls that are applied infrequently, for example, quarterly, or when evidence regarding application of the control makes 100% examination efficient;
(b)
Selecting specific items. This may be appropriate where 100% examination would not be efficient and sampling would not be effective, such as testing controls that are not applied sufficiently frequently to render a large population for sampling, for example, controls that are applied monthly or weekly; and
(c)
Sampling. This may be appropriate for testing controls that are applied frequently in a uniform manner and which leave documentary evidence of their application.
(a)
Contains a materially false or misleading statement;
(b)
Contains statements or information furnished negligently; or
(c)
Omits or obscures information required to be included where such omission or obscurity would be misleading14. If other information included in a document containing the service organization’s description of its system and the service auditor’s assurance report contains future-oriented information such as recovery or contingency plans, or plans for modifications to the system that will address deviations identified in the service auditor’s assurance report, or claims of a promotional nature that cannot be reasonably substantiated, the service auditor may request that information be removed or restated.
(a)
The accompanying description at pages [bb-cc] fairly presents [the type or name of] system for processing customers’ transactions throughout the period [date] to [date]. The criteria used in making this assertion were that the accompanying description:
(i)
Presents how the system was designed and implemented, including: The types of services provided, including, as appropriate, classes of transactions processed.
(ii)
(iii)
Does not omit or distort information relevant to the scope of the system being described, while acknowledging that the description is prepared to meet the common needs of a broad range of customers and their auditors and may not, therefore, include every aspect of the system that each individual customer may consider important in its own particular environment.
(b)
The controls related to the control objectives stated in the accompanying description were suitably designed and operated effectively throughout the period [date] to [date]. The criteria used in making this assertion were that:
(i)
(ii)
(iii)
The controls were consistently applied as designed, including that manual controls were applied by individuals who have the appropriate competence and authority, throughout the period [date] to [date].
(a)
The accompanying description at pages [bb-cc] fairly presents [the type or name of] system for processing customers’ transactions as at [date]. The criteria used in making this assertion were that the accompanying description:
(i)
Presents how the system was designed and implemented, including: The types of services provided, including, as appropriate, classes of transactions processed.
(ii)
Does not omit or distort information relevant to the scope of the system being described, while acknowledging that the description is prepared to meet the common needs of a broad range of customers and their auditors and may not, therefore, include every aspect of the system that each individual customer may consider important in its own particular environment.
(b)
The controls related to the control objectives stated in the accompanying description were suitably designed as at [date]. The criteria used in making this assertion were that:
(i)
(ii)
(a)
The description fairly presents the [the type or name of] system as designed and implemented throughout the period from [date] to [date];
(b)
The controls related to the control objectives stated in the description were suitably designed throughout the period from [date] to [date]; and
(c)
The controls tested, which were those necessary to provide reasonable assurance that the control objectives stated in the description were achieved, operated effectively throughout the period from [date] to [date].
(a)
The description fairly presents the [the type or name of] system as designed and implemented as at [date]; and
(b)
The controls related to the control objectives stated in the description were suitably designed as at [date].
(a)
… Example 2: Qualified opinion – the controls are not suitably designed to provide reasonable assurance that the control objectives stated in the service organization’s description of its system will be achieved if the controls operate effectively …
(a)
… Example 3: Qualified opinion – the controls did not operate effectively throughout the specified period (type 2 report only) …
(a)
…
Notes, amendments & references (6)
2 SA 402, “Audit Considerations Relating to an Entity Using a Service Organization”.
13 SA 315, “Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and Its Environment”.
15 SQC 1, paragraph 74.
16 SQC 1, paragraph 75.
18 Partner or Proprietor, as the case may be.
20 Partner or Proprietor, as the case may be.