CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium

During the planning phase of an audit, an auditor notes that a client, a manufacturing company, has recently outsourced its entire IT infrastructure to a third-party service organization. The auditor's primary concern regarding this change, from a risk assessment perspective, should be related to the potential impact on:

  1. AThe effectiveness of the company's internal controls over financial reporting.
  2. BThe availability of qualified personnel within the company's accounting department.
  3. CThe accuracy of the company's quarterly financial forecasts.
  4. DThe company's ability to generate sufficient revenue.
Show answer & explanation

Correct answer: A. The effectiveness of the company's internal controls over financial reporting.

Outsourcing IT infrastructure often means that key controls over data processing, system access, and data integrity are now performed by a third party. This directly impacts the client's internal controls over financial reporting, requiring the auditor to understand and evaluate the service organization's controls.

Why the other options are wrong

  • B. Outsourcing IT might reduce the need for internal IT personnel but does not directly impact the qualification of accounting department personnel; rather, it shifts the focus to understanding the service organization's personnel and controls.
  • C. Financial forecasts are management's responsibility and are not directly impacted by IT infrastructure outsourcing in the same way that internal controls over financial reporting are.
  • D. While IT infrastructure can support revenue generation, the direct and primary risk to the audit, from an outsourcing perspective, is not revenue sufficiency but control effectiveness.

Service Organization Controls

When an entity uses a service organization (e.g., for IT, payroll), the auditor must consider the impact of the service organization's controls on the user entity's internal controls over financial reporting.

  • Auditor must obtain an understanding of the service organization's controls.
  • This understanding is crucial for assessing control risk at the user entity.
  • Often obtained through a SOC 1 report (Service Organization Control report).

Memory trick: Outsourced IT means your controls are 'SOC'ked up if you don't check them.

More Assessing Risk and Developing a Planned Response questions