18. If the user auditor plans to use a Type 1 or a Type 2 report that excludes the services provided by a subservice organisation and those services are relevant to the audit of the user entity’s financial statements, the user auditor shall apply the requirements of this SA with respect to the services provided by the subservice organisation. (Ref: Para. A40)
Fraud, Non-Compliance with Laws and Regulations and
Uncorrected Misstatements in Relation to Activities at the Service
19. The user auditor shall inquire of management of the user entity whether the service organisation has reported to the user entity, or whether the user entity is otherwise aware of, any fraud, non-compliance with laws and regulations or uncorrected misstatements affecting the financial statements of the user entity. The user auditor shall evaluate how such matters affect the nature, timing and extent of the user auditor’s further audit procedures, including the effect on the user auditor’s conclusions and user auditor’s report. (Ref: Para. A41)
Reporting by the User Auditor
20. The user auditor shall modify the opinion in the user auditor’s report in accordance with SA 705(Revised)5 if the user auditor is unable to obtain sufficient appropriate audit evidence regarding the services provided by the service organisation relevant to the audit of the user entity’s financial statements. (Ref: Para. A42)
21. The user auditor shall not refer to the work of a service auditor in the user auditor’s report containing an unmodified opinion unless required by law or regulation to do so. If such reference is required by law or regulation, the user auditor’s report shall indicate that the reference does not diminish the user auditor’s responsibility for the audit opinion. (Ref: Para. A43)
22. If reference to the work of a service auditor is relevant to an understanding 5 SA 705(Revised), “Modifications to the Opinion in the Independent Auditor’s Report”, paragraph 6. of a modification to the user auditor’s opinion, the user auditor’s report shall indicate that such reference does not diminish the user auditor’s responsibility for that opinion. (Ref: Para. A44) ***
Application and Other Explanatory Material
Obtaining an Understanding of the Services Provided by a Service
Organisation, Including Internal Control
Sources of Information (Ref: Para. 9)
A1. Information on the nature of the services provided by a service organisation may be available from a wide variety of sources, such as: User manuals. System overviews. Technical manuals. The contract or service level agreement between the user entity and the service organisation. Reports by service organisations, internal auditors or regulatory authorities on controls at the service organisation. Reports by the service auditor, including management letters, if available.
A2. Knowledge obtained through the user auditor’s experience with the service organisation, for example through experience with other audit engagements, may also be helpful in obtaining an understanding of the nature of the services provided by the service organisation. This may be particularly helpful if the services and controls at the service organisation over those services are highly standardised. Nature of the Services Provided by the Service Organisation (Ref: Para. 9(a))
A3. A user entity may use a service organisation such as one that processes transactions and maintains related accountability, or records transactions and processes related data. Service organisations that provide such services include, for example, bank trust departments that invest and service assets for employee benefit plans or for others; mortgage bankers that service mortgages for others; and application service providers that provide packaged software applications and a technology environment that enables customers to process financial and operational transactions.
A4. Examples of service organisation services that are relevant to the audit include: Maintenance of the user entity’s accounting records. Management of assets. Initiating, recording or processing transactions as agent of the user entity.
Considerations Specific to Smaller Entities
A5. Smaller entities may use external bookkeeping services ranging from the processing of certain transactions (e.g., payment of payroll taxes) and maintenance of their accounting records to the preparation of their financial statements. The use of such a service organisation for the preparation of its financial statements does not relieve management of the smaller entity and, where appropriate, those charged with governance of their responsibilities for the financial statements.6
Nature and Materiality of Transactions Processed by the Service
Organisation (Ref: Para. 9(b))
A6. A service organisation may establish policies and procedures that affect the user entity’s internal control. These policies and procedures are at least in part physically and operationally separate from the user entity. The significance of the controls of the service organisation to those of the user entity depends on the nature of the services provided by the service organisation, including the nature and materiality of the transactions it processes for the user entity. In certain situations, the transactions processed and the accounts affected by the service organisation may not appear to be material to the user entity’s financial statements, but the nature of the transactions processed may be significant and the user auditor may determine that an understanding of those controls is necessary in the circumstances.
The Degree of Interaction between the Activities of the Service
Organisation and the User Entity (Ref: Para. 9(c))
A7. The significance of the controls of the service organisation to those of the user entity also depends on the degree of interaction between its activities and those of the user entity. The degree of interaction refers to the extent to which a user entity is able to and elects to implement effective controls over the processing performed by the service organisation. For example, a high degree of interaction exists between the activities of the user entity and those at the service organisation when the user entity authorises transactions and the service organisation processes and does the accounting for those transactions. In these circumstances, it may be practicable for the 6 SA 200, paragraph 4 and A2-A3. user entity to implement effective controls over those transactions. On the other hand, when the service organisation initiates or initially records, processes, and does the accounting for the user entity’s transactions, there is a lower degree of interaction between the two organisations. In these circumstances, the user entity may be unable to, or may elect not to, implement effective controls over these transactions at the user entity and may rely on controls at the service organisation. Nature of the Relationship between the User Entity and the Service
Organisation (Ref: Para. 9(d))
A8. The contract or service level agreement between the user entity and the service organisation may provide for matters such as: The information to be provided to the user entity and responsibilities for initiating transactions relating to the activities undertaken by the service organisation;
The application of requirements of regulatory bodies concerning the
form of records to be maintained, or access to them; The indemnification, if any, to be provided to the user entity in the event of a performance failure; Whether the service organisation will provide a report on its controls and, if so, whether such report would be a Type 1 or Type 2 report; Whether the user auditor has rights of access to the accounting records of the user entity maintained by the service organisation and other information necessary for the conduct of the audit; and
Whether the agreement allows for direct communication between the
user auditor and the service auditor.
A9. There is a direct relationship between the service organisation and the user entity and between the service organisation and the service auditor. These relationships do not necessarily create a direct relationship between the user auditor and the service auditor. When there is no direct relationship between the user auditor and the service auditor, communications between the user auditor and the service auditor are usually conducted through the user entity and the service organisation. A direct relationship may also be created between a user auditor and a service auditor, taking into account the relevant ethical and confidentiality considerations. A user auditor, for example, may use a service auditor to perform procedures on the user auditor’s behalf, such as: