ISAE 3402
Assurance Reports on Controls at a Service Organization
1Objective and scope
ISAE 3402 deals with assurance engagements undertaken by a professional accountant in public practice to provide a report for use by user entities and their auditors on the controls at a service organisation that provides a service to user entities that is likely to be relevant to user entities' internal control as it relates to financial reporting. It is the counterpart of ISA 402: ISA 402 tells the user auditor how to use a service auditor's report, ISAE 3402 tells the service auditor how to produce one. It complements ISAE 3000 (Revised) and is a reasonable assurance engagement. It covers Type 1 and Type 2 reports; it does not cover assurance on controls unrelated to financial reporting (operational or compliance controls), on controls at a user entity, or agreed-upon procedures on controls, though it may be applied by analogy with adaptation. A service organisation (a payroll bureau, a fund administrator, a data centre, a mobile-money processor, a claims handler) obtains one ISAE 3402 report and gives it to every user entity's auditor, instead of hosting dozens of separate audits.
The objectives of the service auditor are to obtain reasonable assurance about whether, in all material respects, based on suitable criteria, the service organisation's description of its system fairly presents the system as designed and implemented throughout the specified period (or as at a specified date for a Type 1 report); the controls related to the control objectives stated in the description were suitably designed throughout the period (or at the date); and, for a Type 2 report, the controls operated effectively to provide reasonable assurance that the control objectives stated in the description were achieved throughout the period; and to report in accordance with the findings.
2Key definitions
3Requirements
Acceptance and the criteria
- Accept or continue only if the service auditor has the capabilities and competence, the criteria to be applied are suitable and will be available to the intended users, and the scope of the engagement and the description of the system will not be so limited as to be unlikely to be useful to user entities and their auditors.
- Obtain the service organisation's agreement that it acknowledges and accepts responsibility for preparing the description and the accompanying assertion, for having a reasonable basis for the assertion, for stating the criteria used in the description, for identifying the risks that threaten the achievement of the control objectives and designing and implementing controls to provide reasonable assurance of achieving them, and for providing access to all relevant information and persons.
- Assess whether the criteria are suitable for the description (a fair presentation), for the design (the controls, if operated as described, would provide reasonable assurance of achieving the control objectives), and for operating effectiveness (the controls were consistently applied as designed, including manual controls being applied by persons with appropriate competence and authority).
- If the service organisation requests a change in scope after acceptance, agree only where there is reasonable justification; a request to change from a Type 2 to a Type 1 because deviations were found is not reasonable justification.
Obtaining evidence
- On the description: read it and evaluate whether the aspects included are presented at a level of detail that could reasonably be expected to provide sufficient information for user auditors to understand the services and to consider the effect on their risk assessment; determine through inquiry, observation, inspection of records and documents, and walkthroughs whether the system has been implemented as described; and evaluate whether the control objectives stated are reasonable in the circumstances, whether complementary user entity controls are appropriately identified, and whether the subservice organisation treatment is properly disclosed.
- On the design: determine which of the controls at the service organisation are necessary to achieve the control objectives, and assess whether those controls were suitably designed by identifying the risks that threaten the objectives and evaluating the linkage of the controls to the risks.
- On operating effectiveness (Type 2): test the controls the service auditor has determined are necessary to achieve the control objectives, throughout the period, and obtain evidence about how the controls were applied, the consistency of application and by whom or what means; inquiry alone is not sufficient. Where a control depends on other controls (general IT controls, a review of exception reports), obtain evidence about those too. Determine the extent of testing (sample sizes) by reference to the frequency of the control, the length of the period, the expected deviation rate, the relevance and reliability of the evidence, and the extent to which evidence from other tests supports the control.
- Investigate the nature and cause of any deviations identified and determine whether the deviations are within the expected rate, whether additional testing is needed, and whether they mean the control did not operate effectively throughout the period. Deviations, including those the service organisation subsequently remediated, are reported in the description of tests and results.
- Use of internal audit: where the service organisation has an internal audit function, the service auditor may use its work (evaluating objectivity, competence and systematic approach as under ISA 610), but the report must describe the work of internal audit that was used and the service auditor's procedures on it; direct assistance is used only within the same constraints.
- Obtain written representations from the service organisation reaffirming the assertion, and stating that it has provided all relevant information and access and that it has disclosed any non-compliance, fraud, uncorrected deviations or subsequent events known to it that could affect the report. A refusal produces a qualified opinion or a disclaimer, or withdrawal.
- Inquire about subsequent events up to the date of the report that could have a significant effect on the assertion (a system change, a data breach, a change of control), and consider whether any needs to be disclosed.
- Read other information included in the document containing the description for material inconsistency with the description or the report.
4Documentation and reporting
A Type 2 report contains: a title indicating an independent service auditor's assurance report; an addressee; identification of the description of the system and the management assertion, and of any parts of the description not covered by the opinion (carved-out subservice organisations, or a function outside the scope); identification of the criteria and the party specifying the control objectives; a statement that the report and the description of tests are intended only for user entities and their auditors who have a sufficient understanding to consider it, along with other information, in assessing the risks of material misstatement of user entities' financial statements (a restriction on use); a statement that the service organisation is responsible for the description, the assertion, providing the services, stating the control objectives and designing and implementing controls; a statement that the service auditor's responsibility is to express an opinion, that the engagement was conducted in accordance with ISAE 3402, that the service auditor complies with ISQM 1 and the independence requirements, and a summary of the procedures; a statement of the inherent limitations of controls, and that the projection to future periods of any evaluation is subject to the risk that controls become inadequate or fail; the service auditor's opinion on the three matters, throughout the period; a description of the tests of controls performed and their results, with the deviations noted; the date; and the signature and location. A Type 1 report omits the operating effectiveness opinion and the tests and results, and speaks as at a date. Where the description is not fairly presented, the controls are not suitably designed, or they did not operate effectively, or the service auditor cannot obtain sufficient appropriate evidence, the opinion is modified (qualified, adverse or disclaimer) with a basis section explaining the reasons, and the description of tests and results still identifies every deviation. Documentation follows ISAE 3000 and ISA 230 principles, and where the work of internal audit was used, records the evaluation and the procedures on it.
5Examinable focus
What KASNEB tests
Usually paired with ISA 402 in one question: from the service auditor's side, the acceptance conditions, the service organisation's responsibilities (description, assertion, control objectives), the procedures on description, design and operating effectiveness, and the contents of a Type 2 report including the restriction on use and the description of tests; from the user auditor's side, how the report is evaluated and used. Know the Type 1 versus Type 2 difference cold, the carve-out versus inclusive treatment of subservice organisations, complementary user entity controls, and the rule that a downgrade from Type 2 to Type 1 to hide deviations is not reasonable justification. Kenyan examples the examiner uses: outsourced payroll, a pension fund administrator, a bank's core banking hosted by a vendor, and a mobile-money aggregator.