CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium

An auditor is assessing control risk for a client's payroll process. The client uses a third-party payroll service provider for all payroll calculations, tax filings, and direct deposits. The auditor's primary approach to assessing the effectiveness of controls related to these outsourced functions would typically involve:

  1. AReviewing the client's internal controls over authorizing employee hours and changes.
  2. BInterviewing the client's employees about their satisfaction with the payroll service.
  3. CObtaining and reviewing a Service Organization Control (SOC 1) report from the service provider.
  4. DPerforming extensive re-calculations of payroll for a sample of employees.
Show answer & explanation

Correct answer: C. Obtaining and reviewing a Service Organization Control (SOC 1) report from the service provider.

For outsourced functions, auditors typically rely on SOC 1 reports (Type 1 or Type 2) from the service organization. These reports provide information and assurance about the controls at the service organization that are relevant to the user entity's financial reporting.

Why the other options are wrong

  • A. This addresses the client's internal controls, which are important, but not the controls *at the service provider* that handle calculations and deposits.
  • B. Employee satisfaction is not an audit procedure for assessing the effectiveness of internal controls over financial reporting.
  • D. While some recalculations might be done, the primary way to assess controls of an outsourced function is through a SOC report, not by re-performing the entire process.

SOC 1 Report

A Service Organization Control (SOC) 1 report provides user entities and their auditors with information about the controls at a service organization that are relevant to a user entity's internal control over financial reporting.

  • Type 1 reports describe controls at a point in time.
  • Type 2 reports describe controls over a period and include tests of operating effectiveness.
  • Helps the user auditor understand and assess control risk related to outsourced functions.

Memory trick: Outsourced payroll? Get a 'SOC 1' to 'CHECK' their controls.

More Assessing Risk and Developing a Planned Response questions