CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium

A client, a multinational manufacturing company, has recently outsourced its entire IT infrastructure, including data centers and network management, to a third-party service organization. When developing the audit plan, how should the auditor primarily address the risks associated with this outsourcing arrangement?

  1. APerform detailed walkthroughs of the client's remaining internal controls over financial reporting.
  2. BObtain and review a Service Organization Control (SOC) 1 report, Type 2, from the service organization.
  3. CRequest direct access to the service organization's systems and data for audit testing purposes.
  4. DIncrease the scope of substantive testing on all financial statement accounts directly impacted by the outsourced IT processes.
Show answer & explanation

Correct answer: B. Obtain and review a Service Organization Control (SOC) 1 report, Type 2, from the service organization.

When a client uses a third-party service organization for processes relevant to financial reporting, the auditor's primary responsibility is to understand the controls at the service organization. A SOC 1, Type 2 report provides assurance on the design and operating effectiveness of these controls.

Why the other options are wrong

  • A. Walkthroughs of the client's internal controls are important, but they don't provide sufficient assurance over controls operated by the third-party service organization.
  • C. Direct access to a service organization's systems is generally not granted to the client's auditor and is not a standard audit procedure for assessing service organization controls.
  • D. While substantive testing may be increased, it's not the primary or most efficient way to address risks related to outsourced IT infrastructure when a SOC report is available.

Service Organization Control (SOC) 1 Report

A report issued by a service organization's auditor to provide information about the service organization's internal controls over financial reporting relevant to a user entity's financial statements.

  • Type 1 reports on design of controls at a specific date.
  • Type 2 reports on design and operating effectiveness over a period.
  • Essential for auditing clients using outsourced services impacting financial reporting.

Memory trick: SOC-kets connect client to service controls.

More Assessing Risk and Developing a Planned Response questions