Audit Considerations Relating to an Entity Using a Service Organisation
(a)
The classes of transactions in the user entity’s operations that are significant to the user entity’s financial statements;
(b)
The procedures, within both information technology (IT) and manual systems, by which the user entity’s transactions are initiated, recorded, processed, corrected as necessary, transferred to the general ledger and reported in the financial statements;
(c)
The related accounting records, either in electronic or manual form, supporting information and specific accounts in the user entity’s financial statements that are used to initiate, record, process and report the user entity’s transactions; this includes the correction of incorrect information and how information is transferred to the general ledger;
(d)
How the user entity’s information system captures events and conditions, other than transactions, that are significant to the financial statements;
(e)
The financial reporting process used to prepare the user entity’s financial statements, including significant accounting estimates and disclosures; and
(f)
Controls surrounding journal entries, including non-standard journal entries used to record non-recurring, unusual transactions or adjustments.
(a)
To obtain an understanding of the nature and significance of the services provided by the service organisation and their effect on the user entity’s internal control relevant to the audit, sufficient to identify and assess the risks of material misstatement; and
(b)
To design and perform audit procedures responsive to those risks.
(a)
Complementary user entity controls – Controls that the service organisation assumes, in the design of its service, will be implemented by user entities, and which, if necessary to achieve control objectives, are identified in the description of its system.
(b)
Report on the description and design of controls at a service organisation (referred to in this SA as a Type 1 report) – A report that comprises:
(i)
A description, prepared by management of the service organisation, of the service organisation’s system, control objectives and related controls that have been designed and implemented as at a specified date; and
(ii)
A report by the service auditor with the objective of conveying reasonable assurance that includes the service auditor’s opinion on the description of the service organisation’s system, control objectives and related controls and the suitability of the design of the controls to achieve the specified control objectives.
(c)
Report on the description, design, and operating effectiveness of controls at a service organisation (referred to in this SA as a Type 2 report) – A report that comprises:
(i)
A description, prepared by management of the service organisation, of the service organisation’s system, control objectives and related controls, their design and implementation as at a specified date or throughout a specified period and, in some cases, their operating effectiveness throughout a specified period; and
(ii)
A report by the service auditor with the objective of conveying reasonable assurance that includes: a.
(d)
Service auditor – An auditor who, at the request of the service organisation, provides an assurance report on the controls of a service organisation.
(e)
Service organisation – A third-party organisation (or segment of a third-party organisation) that provides services to user entities that are part of those entities’ information systems relevant to financial reporting.
(f)
Service organisation’s system – The policies and procedures designed, implemented and maintained by the service organisation to provide user entities with the services covered by the service auditor’s report.
(g)
Subservice organisation – A service organisation used by another service organisation to perform some of the services provided to user entities that are part of those user entities’ information systems relevant to financial reporting.
(h)
User auditor – An auditor who audits and reports on the financial statements of a user entity.
(i)
User entity – An entity that uses a service organisation and whose financial statements are being audited.
(a)
The nature of the services provided by the service organisation and the significance of those services to the user entity, including the effect thereof on the user entity’s internal control; (Ref: Para. A3-A5)
(b)
The nature and materiality of the transactions processed or accounts or financial reporting processes affected by the service organisation; (Ref:
(c)
The degree of interaction between the activities of the service organisation and those of the user entity; and (Ref: Para. A7)
(d)
The nature of the relationship between the user entity and the service organisation, including the relevant contractual terms for the activities undertaken by the service organisation. (Ref: Para. A8-A11)
(a)
Obtaining a Type 1 or Type 2 report, if available;
(b)
Contacting the service organisation, through the user entity, to obtain specific information;
(c)
(d)
Using another auditor to perform procedures that will provide the necessary information about the relevant controls at the service organisation. Using a Type 1 or Type 2 Report to Support the User Auditor’s
(a)
The service auditor’s professional competence (except where the service auditor is a member of the Institute of Chartered Accountants of India) and independence from the service organisation; and
(b)
The adequacy of the standards under which the Type 1 or Type 2 report was issued.
(a)
Evaluate whether the description and design of controls at the service organisation is at a date or for a period that is appropriate for the user auditor’s purposes;
(b)
Evaluate the sufficiency and appropriateness of the evidence provided by the report for the understanding of the user entity’s internal control relevant to the audit; and
(c)
(a)
Determine whether sufficient appropriate audit evidence concerning the relevant financial statement assertions is available from records held at the user entity; and, if not,
(b)
Perform further audit procedures to obtain sufficient appropriate audit evidence or use another auditor to perform those procedures at the service organisation on the user auditor’s behalf.
(a)
Obtaining a Type 2 report, if available;
(b)
Performing appropriate tests of controls at the service organisation; or
(c)
Using another auditor to perform tests of controls at the service organisation on behalf of the user auditor. Using a Type 2 Report as Audit Evidence that Controls at the Service
(a)
Evaluating whether the description, design and operating effectiveness of controls at the service organisation is at a date or for a period that is appropriate for the user auditor’s purposes;
(b)
Determining whether complementary user entity controls identified by the service organisation are relevant to the user entity and, if so, obtaining an understanding of whether the user entity has designed and implemented such controls and, if so, testing their operating effectiveness;
(c)
Evaluating the adequacy of the time period covered by the tests of controls and the time elapsed since the performance of the tests of controls; and
(d)
Evaluating whether the tests of controls performed by the service auditor and the results thereof, as described in the service auditor’s report, are relevant to the assertions in the user entity’s financial statements and provide sufficient appropriate audit evidence to support the user auditor’s risk assessment. Type 1 and Type 2 Reports that Exclude the Services of a Subservice
(a)
Tests of controls at the service organisation; or
(b)
Substantive procedures on the user entity’s financial statement transactions and balances maintained by a service organisation.
(a)
The aspects of controls at the service organisation that may affect the processing of the user entity’s transactions, including the use of subservice organisations;
(b)
The flow of significant transactions through the service organisation to determine the points in the transaction flow where material misstatements in the user entity’s financial statements could occur;
(c)
The control objectives at the service organisation that are relevant to the user entity’s financial statement assertions; and
(d)
Whether controls at the service organisation are suitably designed and implemented to prevent or detect processing errors that could result in material misstatements in the user entity’s financial statements. A Type 1 or Type 2 report may assist the user auditor in obtaining a sufficient understanding to identify and assess the risks of material misstatement. A type 1 report, however, does not provide any evidence of the operating effectiveness of the relevant controls.
(a)
Inspecting records and documents held by the user entity: the reliability of this source of evidence is determined by the nature and extent of the accounting records and supporting documentation retained by the user entity. In some cases, the user entity may not maintain independent detailed records or documentation of specific transactions undertaken on its behalf.
(b)
Inspecting records and documents held by the service organisation: the user auditor’s access to the records of the service organisation may be established as part of the contractual arrangements between the user entity and the service organisation. The user auditor may also use another auditor, on its behalf, to gain access to the user entity’s records maintained by the service organisation.
(c)
(d)
Performing analytical procedures on the records maintained by the user entity or on the reports received from the service organisation: the effectiveness of analytical procedures is likely to vary by assertion and will be affected by the extent and detail of information available.
(a)
The user auditor’s assessment of risks of material misstatement includes an expectation that the controls at the service organisation are operating effectively (i.e., the user auditor intends to rely on the operating effectiveness of controls at the service organisation in determining the nature, timing and extent of substantive procedures); or
(b)
Substantive procedures alone, or in combination with tests of the operating effectiveness of controls at the user entity, cannot provide sufficient appropriate audit evidence at the assertion level.
(a)
The time period covered by the tests of controls and the time elapsed since the performance of the tests of controls;
(b)
The scope of the service auditor’s work and the services and processes covered, the controls tested and tests that were performed, and the way in which tested controls relate to the user entity’s controls; and
(c)
The results of those tests of controls and the service auditor’s opinion on the operating effectiveness of the controls.
Notes, amendments & references (12)
1 SA 315, “Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and Its Environment”.
2 SA 330, “The Auditor’s Responses to Assessed Risks”.
3 SA 315, paragraph 11.
4 SA 315, paragraph 12.
5 SA 705(Revised), “Modifications to the Opinion in the Independent Auditor’s Report”, paragraph 6.
6 SA 200, paragraph 4 and A2-A3.
7 SA 315, paragraph 30.
8 SAE 3402, Assurance Reports on Controls at a Service Organisation.
9 SA 600, Using the Work of Another Auditor.
11 SA 330, paragraph 8.
12 SA 265, “Communicating Deficiencies in Internal Control to Those Charged with Governance and Management”, paragraph 9 and 10.
13 SA 265, paragraph 9.