ISA 402
Audit Considerations Relating to an Entity Using a Service Organization
1Objective and scope
ISA 402 deals with the user auditor's responsibility to obtain sufficient appropriate audit evidence when a user entity uses the services of one or more service organisations. It expands on how ISA 315 and ISA 330 are applied in obtaining an understanding of the user entity, including internal control relevant to the audit that is located at the service organisation, and in responding to the assessed risks. Services are relevant when they are part of the user entity's information system for financial reporting: payroll bureaux, outsourced accounting, custodians and fund administrators, cloud-hosted ERP and data centres, claims processing, mobile-money and card processors. Services limited to processing transactions specifically authorised by the entity (a bank processing cheques) are not in scope unless they include the entity's records.
The objectives of the user auditor are to obtain an understanding of the nature and significance of the services provided by the service organisation and their effect on the user entity's internal control relevant to the audit, sufficient to identify and assess the risks of material misstatement; and to design and perform audit procedures responsive to those risks.
2Key definitions
3Requirements
Obtaining an understanding
- Understand the nature of the services and their significance to the user entity; the nature and materiality of the transactions processed or the accounts or financial reporting processes affected; the degree of interaction between the user entity's activities and the service organisation's; and the nature of the relationship, including the contractual terms.
- Evaluate the design and implementation of relevant controls at the user entity that relate to the services provided, including complementary user entity controls (for example, the user entity's review of payroll output before payment).
- If the user entity's own controls and information do not give a sufficient understanding, obtain it from one or more of: a Type 1 or Type 2 report; contacting the service organisation through the user entity; visiting the service organisation and performing procedures; or using another auditor to perform procedures there.
- In using a Type 1 or Type 2 report to obtain an understanding, be satisfied about the service auditor's professional competence and independence and the adequacy of the standards under which the report was issued; evaluate whether the description is at a date or for a period appropriate to the audit, whether complementary user entity controls are relevant and, if so, whether the user entity has implemented them, and whether the report gives sufficient evidence for the understanding.
Responding to the assessed risks
The user auditor determines whether sufficient appropriate evidence about the relevant assertions is available from records held at the user entity; if not, the auditor performs further procedures at the service organisation or uses another auditor to do so. Where the user auditor's risk assessment includes an expectation that controls at the service organisation are operating effectively, the user auditor obtains evidence about operating effectiveness from one or more of: a Type 2 report; appropriate tests of controls at the service organisation performed by the user auditor; or tests performed by another auditor on the user auditor's behalf.
- In using a Type 2 report as evidence of operating effectiveness, determine whether it covers the appropriate period and whether the controls tested are relevant to the user entity's assertions; evaluate the time elapsed since the period covered, the length of the period, and whether complementary user entity controls have been implemented; evaluate the adequacy of the tests performed and their results, including any deviations and their implications.
- Inquire of the user entity's management whether the service organisation has reported any fraud, non-compliance with laws and regulations, or uncorrected misstatements affecting the user entity, and evaluate the effect on the nature, timing and extent of further procedures and on the auditor's report.
- Where the report's period does not match the user entity's period (a report to 30 September for a 31 December year end), obtain additional evidence for the gap: inquiries, a bridging letter from the service organisation, tests of the user entity's monitoring controls, or tests at the service organisation.
4Documentation and reporting
The user auditor's report must not refer to the work of the service auditor unless required by law or regulation, and even then the reference does not diminish the user auditor's responsibility for the opinion (the same rule as ISA 620 for experts). If sufficient appropriate evidence about the services cannot be obtained from the user entity's records, from a service auditor's report or from procedures at the service organisation, the opinion is modified for a limitation on scope under ISA 705. The audit file records the understanding of the services and controls, the evaluation of any Type 1 or Type 2 report (including the service auditor's competence and independence and the period covered), the complementary user entity controls considered, the procedures performed for any gap period, and the conclusions on reliance.
5Examinable focus
What KASNEB tests
The examiner's favourite is the Type 1 versus Type 2 distinction and the audit evidence each provides (design only versus design and operating effectiveness), followed by 'what factors would you consider before relying on a service auditor's report' (competence, independence, standards used, period covered, tests performed, complementary user controls, subservice organisations). Scenarios give an outsourced payroll bureau, a cloud accounting provider or a fund custodian, and ask how the user auditor plans the audit of the affected balances and what to do when the report period does not match the year end. Remember that the user auditor never mentions the service auditor in the report and remains solely responsible for the opinion.