CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium
A client, a multinational manufacturing company, has recently outsourced its entire IT infrastructure, including data centers and network management, to a third-party service organization. When developing the audit plan, how should the auditor primarily address the risks associated with this outsourcing arrangement?
- APerform detailed walkthroughs of the client's remaining internal controls over financial reporting.
- BObtain and review a Service Organization Control (SOC) 1 report, Type 2, from the service organization.
- CRequest direct access to the service organization's systems and data for audit testing purposes.
- DIncrease the scope of substantive testing on all financial statement accounts directly impacted by the outsourced IT processes.
Show answer & explanationAnswer & explanation
Correct answer: B. Obtain and review a Service Organization Control (SOC) 1 report, Type 2, from the service organization.
When a client uses a third-party service organization for processes relevant to financial reporting, the auditor's primary responsibility is to understand the controls at the service organization. A SOC 1, Type 2 report provides assurance on the design and operating effectiveness of these controls.
Why the other options are wrong
- A. Walkthroughs of the client's internal controls are important, but they don't provide sufficient assurance over controls operated by the third-party service organization.
- C. Direct access to a service organization's systems is generally not granted to the client's auditor and is not a standard audit procedure for assessing service organization controls.
- D. While substantive testing may be increased, it's not the primary or most efficient way to address risks related to outsourced IT infrastructure when a SOC report is available.
Service Organization Control (SOC) 1 Report
A report issued by a service organization's auditor to provide information about the service organization's internal controls over financial reporting relevant to a user entity's financial statements.
- Type 1 reports on design of controls at a specific date.
- Type 2 reports on design and operating effectiveness over a period.
- Essential for auditing clients using outsourced services impacting financial reporting.
Memory trick: SOC-kets connect client to service controls.