includes whether manual controls were applied by individuals who have the appropriate competence and authority.
the criteria for this opinion are met, controls will have provided reasonable assurance that the related control objectives were achieved throughout the specified period. (The subject matter information for this opinion is the service organization’ s assertion that controls are suitably designed and that they are operating effectively.)
control objectives, which are stated in the service organizati on’s descriptio n of its system, are part of the criteria for these opinions.
control objectives will differ from engageme nt to engageme nt. If, as part of forming the opinion on the descriptio n, the service auditor concludes the stated control objectives are not fairly presented
these criteria suitabi- lity of design (type 1 reports) of those controls that are necessary to achieve the control objectives stated in the service organization’s description of its system. if: (a) the service organization has identified the risks that threaten achievement of the control objectives stated in the description of its system; and (b) the controls identified in that description would, if operated as described, provide reasonable assurance that those risks do not prevent the stated control objectives from being achieved. does not, of itself, provide any assurance that the related control objectives were achieved because no assurance has been obtained about the operation of controls. (The subject matter information for this opinion is the service organization’ s assertion that controls are suitably designed.) then those control objectives would not be suitable as part of the criteria for forming an opinion on either the design or operating effectiven ess of controls.
A15. Paragraph 16(a) identifies a number of elements that are included in the service organization’s description of its system as appropriate. These elements may not be appropriate if the system being described is not a system that processes transactions, for example, if the system relates to general controls over the hosting of an IT application but not the controls embedded in the application itself.
Materiality (Ref: Para. 19 and 54)
A16. In an engagement to report on controls at a service organization, the concept of materiality relates to the system being reported on, not the financial statements of user entities. The service auditor plans and performs procedures to determine whether the service organization’s description of its system is fairly presented in all material respects, whether controls at the service organization are suitably designed in all material respects and, in the case of a type 2 report, whether controls at the service organization are operating effectively in all material respects. The concept of materiality takes into account that the service auditor’s assurance report provides information about the service organization’s system to meet the common information needs of a broad range of user entities and their auditors who have an understanding of the manner in which that system has been used.
A17. Materiality with respect to the fair presentation of the service organization’s description of its system, and with respect to the design of controls, includes primarily the consideration of qualitative factors, for example: whether the description includes the significant aspects of processing significant transactions; whether the description omits or distorts relevant information; and the ability of controls, as designed, to provide reasonable assurance that control objectives would be achieved. Materiality with respect to the service auditor’s opinion on the operating effectiveness of controls includes the consideration of both quantitative and qualitative factors, for example, the tolerable rate and observed rate of deviation (a quantitative matter), and the nature and cause of any observed deviation (a qualitative matter).
A18. The concept of materiality is not applied when disclosing, in the description of the tests of controls, the results of those tests where deviations have been identified. This is because, in the particular circumstances of a specific user entity or user auditor, a deviation may have significance beyond whether or not, in the opinion of the service auditor, it prevents a control from operating effectively. For example, the control to which the deviation relates may be particularly significant in preventing a certain type of error that may be material in the particular circumstances of a user entity’s financial statements.
Obtaining an Understanding of the Service Organization’s System
A19. Obtaining an understanding of the service organization’s system, including controls, included in the scope of the engagement, assists the service auditor in: Identifying the boundaries of that system, and how it interfaces with other systems. Assessing whether the service organization’s description fairly presents the system that has been designed and implemented. Determining which controls are necessary to achieve the control objectives stated in the service organization’s description of its system. Assessing whether controls were suitably designed. Assessing, in the case of a type 2 report, whether controls were operating effectively.
A20. The service auditor’s procedures to obtain this understanding may include: Inquiring of those within the service organization who, in the service auditor’s judgment, may have relevant information.
Observing operations and inspecting documents, reports, printed and
electronic records of transaction processing. Inspecting a selection of agreements between the service organization and user entities to identify their common terms. Reperforming control procedures.
Obtaining Evidence Regarding the Description (Ref: Para. 21-22)
A21. Considering the following questions may assist the service auditor in determining whether those aspects of the description included in the scope of the engagement are fairly presented in all material respects: Does the description address the major aspects of the service provided (within the scope of the engagement) that could reasonably be expected to be relevant to the common needs of a broad range of user auditors in planning their audits of user entities’ financial statements? Is the description prepared at a level of detail that could reasonably be expected to provide a broad range of user auditors with sufficient information to obtain an understanding of internal control in accordance with SA 31513? The description need not address every aspect of the service organization’s processing or the services provided to user entities, and need not be so detailed as to potentially allow a reader to compromise security or other controls at the service organization. Is the description prepared in a manner that does not omit or distort information that may affect the common needs of a broad range of user auditors’ decisions, for example, does the description contain any 13 SA 315, “Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and Its Environment”. significant omissions or inaccuracies in processing of which the service auditor is aware? Where some of the control objectives stated in the service organization’s description of its system have been excluded from the scope of the engagement, does the description clearly identify the excluded objectives?
Have the controls identified in the description been implemented?
Are complementary user entity controls, if any, described adequately? In most cases, the description of control objectives is worded such that the control objectives are capable of being achieved through effective operation of controls implemented by the service organization alone. In some cases, however, the control objectives stated in the service organization’s description of its system cannot be achieved by the service organization alone because their achievement requires particular controls to be implemented by user entities. This may be the case where, for example, the control objectives are specified by a regulatory authority. When the description does include complementary user entity controls, the description separately identifies those controls along with the specific control objectives that cannot be achieved by the service organization alone. If the inclusive method has been used, does the description separately identify controls at the service organization and controls at the subservice organization? If the carve-out method is used, does the description identify the functions that are performed by the subservice organization? When the carve-out method is used, the description need not describe the detailed processing or controls at the subservice organization.
A22. The service auditor’s procedures to evaluate the fair presentation of the description may include: Considering the nature of user entities and how the services provided by the service organization are likely to affect them, for example, whether user entities are from a particular industry and whether they are regulated by government agencies. Reading standard contracts, or standard terms of contracts, (if applicable) with user entities to gain an understanding of the service organization’s contractual obligations. Observing procedures performed by service organization personnel.
Reviewing the service organization’s policy and procedure manuals and
other systems documentation, for example, flowcharts and narratives.
A23. Paragraph 21(a) requires the service auditor to evaluate whether the control objectives stated in the service organization’s description of its system are reasonable in the circumstances. Considering the following questions may assist the service auditor in this evaluation:
Have the stated control objectives been designated by the service
organization or by outside parties such as a regulatory authority, a user group, or a professional body that follows a transparent due process? Where the stated control objectives have been specified by the service organization, do they relate to the types of assertions commonly embodied in the broad range of user entities’ financial statements to which controls at the service organization could reasonably be expected to relate? Although the service auditor ordinarily will not be able to determine how controls at a service organization specifically relate to the assertions embodied in individual user entities’ financial statements, the service auditor’s understanding of the nature of the service organization’s system, including controls, and services being provided is used to identify the types of assertions to which those controls are likely to relate. Where the stated control objectives have been specified by the service organization, are they complete? A complete set of control objectives can provide a broad range of user auditors with a framework to assess the effect of controls at the service organization on the assertions commonly embodied in user entities’ financial statements.
A24. The service auditor’s procedures to determine whether the service organization’s system has been implemented may be similar to, and performed in conjunction with, procedures to obtain an understanding of that system. They may also include tracing items through the service organization’s system and, in the case of a type 2 report, specific inquiries about changes in controls that were implemented during the period. Changes that are significant to user entities or their auditors are included in the description of the service organization’s system.
Obtaining Evidence Regarding Design of Controls (Ref: Para. 23 and
A25. From the viewpoint of a user entity or a user auditor, a control is suitably designed if, individually or in combination with other controls, it would, when complied with satisfactorily, provide reasonable assurance that material misstatements are prevented, or detected and corrected. A service organization or a service auditor, however, is not aware of the circumstances at individual user entities that would determine whether or not a misstatement resulting from a control deviation is material to those user entities. Therefore, from the viewpoint of a service auditor, a control is suitably designed if, individually or in combination with other controls, it would, when complied with satisfactorily, provide reasonable assurance that control objectives stated in the service organization’s description of its system are achieved.
A26. A service auditor may consider using flowcharts, questionnaires, or decision tables to facilitate understanding the design of the controls.
A27. Controls may consist of a number of activities directed at the achievement of a control objective. Consequently, if the service auditor evaluates certain activities as being ineffective in achieving a particular control objective, the existence of other activities may allow the service auditor to conclude that controls related to the control objective are suitably designed.
Obtaining Evidence Regarding Operating Effectiveness of Controls
Assessing Operating Effectiveness (Ref: Para. 24)
A28. From the viewpoint of a user entity or a user auditor, a control is operating effectively if, individually or in combination with other controls, it provides reasonable assurance that material misstatements, whether due to fraud or error, are prevented, or detected and corrected. A service organization or a service auditor, however, is not aware of the circumstances at individual user entities that would determine whether a misstatement resulting from a control deviation had occurred and, if so, whether it is material. Therefore, from the viewpoint of a service auditor, a control is operating effectively if, individually or in combination with other controls, it provides reasonable assurance that control objectives stated in the service organization’s description of its system are achieved. Similarly, a service organization or a service auditor is not in a position to determine whether any observed control deviation would result in a material misstatement from the viewpoint of an individual user entity.
A29. Obtaining an understanding of controls sufficient to opine on the suitability of their design is not sufficient evidence regarding their operating effectiveness, unless there is some automation that provides for the consistent operation of the controls as they were designed and implemented. For example, obtaining information about the implementation of a manual control at a point in time does not provide evidence about operation of the control at other times. However, because of the inherent consistency of IT processing, performing procedures to determine the design of an automated control, and whether it has been implemented, may serve as evidence of that control’s operating effectiveness, depending on the service auditor’s assessment and testing of other controls, such as those over program changes.
A30. To be useful to user auditors, a type 2 report ordinarily covers a minimum period of six months. If the period is less than six months, the service auditor may consider it appropriate to describe the reasons for the shorter period in the service auditor’s assurance report. Circumstances that may result in a report covering a period of less than six months include when (a) the service auditor is engaged close to the date by which the report on controls is to be issued; (b) the service organization (or a particular system or application) has been in operation for less than six months; or (c) significant changes have been made to the controls and it is not practicable either to wait six months before issuing a report or to issue a report covering the system both before and after the changes.
A31. Certain control procedures may not leave evidence of their operation that can be tested at a later date and, accordingly, the service auditor may find it necessary to test the operating effectiveness of such control procedures at various times throughout the reporting period.
A32. The service auditor provides an opinion on the operating effectiveness of controls throughout each period, therefore, sufficient appropriate evidence about the operation of controls during the current period is required for the service auditor to express that opinion. Knowledge of deviations observed in prior engagements may, however, lead the service auditor to increase the extent of testing during the current period.
Testing of Indirect Controls (Ref: Para. 25(b))
A33. In some circumstances, it may be necessary to obtain evidence supporting the effective operation of indirect controls. For example, when the service auditor decides to test the effectiveness of a review of exception reports detailing sales in excess of authorized credit limits, the review and related follow up is the control that is directly of relevance to the service auditor. Controls over the accuracy of the information in the reports (for example, the general IT controls) are described as “indirect” controls.
A34. Because of the inherent consistency of IT processing, evidence about the implementation of an automated application control, when considered in combination with evidence about the operating effectiveness of the service organization’s general controls (in particular, change controls), may also provide substantial evidence about its operating effectiveness. Means of Selecting Items for Testing (Ref: Para. 25(c) and 27)
A35. The means of selecting items for testing available to the service auditor are: