Audit and Assurance · The work of others
Using a Service Organisation's Reports (ISA 402)
Updated 11 October 2026 · Fact-checked
A service organisation does a function for your client, such as payroll. Under ISA 402 the user auditor must understand the service and its controls, then get evidence. You can use a Type 1 report (design) or a Type 2 report (design and operation), or test the controls yourself, or perform substantive procedures at the client.
Understand Using a Service Organisation's Reports
Many clients outsource functions. Payroll, IT hosting, custodianship of investments and processing of transactions are common. The outsourced provider is the service organisation. Your client is the user entity. You, the auditor of the client, are the user auditor.
Outsourcing does not remove your responsibility. The client's transactions still flow into the financial statements. If the service organisation's controls fail, the client's figures may be misstated. So you must understand how the service affects the client's internal control and the risks of material misstatement. You cannot simply say the provider is someone else's problem.
The service organisation often has its own auditor, the service auditor. That auditor can issue an assurance report on the controls. A Type 1 report describes the service organisation's system and reports on whether controls are suitably designed and implemented at a specific date. A Type 2 report covers the same, and also tests whether the controls operated effectively over a period, usually several months. Type 2 gives much more evidence, because you can rely on controls operating effectively.
A report is only useful if you are satisfied with it. You consider the service auditor's professional competence and independence, the standards under which the report was issued, whether the period covered matches the client's year, and whether the controls tested are relevant to your client's assertions. Where the report covers only part of the year, you need extra evidence for the remainder.
If you cannot get sufficient appropriate evidence from a report, you have other options. You can contact the service organisation, via the client, to ask for information. You can visit the service organisation and perform procedures, or ask a service auditor to do so. Or you can test the data held at the client, such as reconciling payroll totals to the ledger. If you cannot obtain enough evidence, you consider the effect on your opinion, which may be modified.
Key rules to remember
- Type 1 report
- Type 1 = description of system + design and implementation of controls at a point in time
- No testing of operating effectiveness. It cannot support reduced substantive testing based on controls working.
- Type 2 report
- Type 2 = Type 1 content + tests of operating effectiveness over a period
- Can be used as evidence that controls operated effectively, if the period and controls are relevant.
- Roles
- User entity = client; user auditor = you; service organisation = provider; service auditor = provider's auditor
- Use these terms exactly in written answers.
- Responsibility
- User auditor's responsibility for the opinion is not reduced by outsourcing
- Do not refer to the service auditor in the audit report on the user entity's statements.
How to solve Using a Service Organisation's Reports questions
Use this method for any question on outsourced functions. It works for scenario questions and written requirements.
- 1Identify the service, who provides it, and which financial statement figures it affects (for example, payroll costs and liabilities).
- 2State that the user auditor must understand the services, their effect on the client's controls and the risks of material misstatement.
- 3Say which evidence is available: Type 1 report, Type 2 report, or none.
- 4Evaluate the report: service auditor's competence and independence, the period covered, the controls tested and the relevance to the client.
- 5Decide what else is needed: tests of the client's own controls over the outsourced work, gaps in the period, or substantive procedures on the data.
- 6Consider alternatives if the report is insufficient: visit the service organisation, use another auditor, or test records at the client.
- 7Conclude on evidence and, if it is insufficient, the effect on the audit opinion.
Quickest way: Report type, then relevance, then gap
When to use it: Use when the question gives a short scenario and asks what the auditor should do about a Type 1 or Type 2 report.
- Ask: is it Type 1 or Type 2? Type 1 means design only. Type 2 means operation too.
- Ask: does the period match the year-end? If not, list the gap and extra procedures.
- Ask: is the service auditor competent and independent, and do the tested controls cover the client's risk?
- Add one fallback: substantive tests on the client's records, such as reconciling the payroll output to the ledger.
Common mistakes in Using a Service Organisation's Reports
Saying the auditor has no responsibility because the function is outsourced.
Students think the service organisation's auditor takes over the work.
Fix: State that the user auditor remains fully responsible for the opinion and must obtain sufficient appropriate evidence.
Treating a Type 1 report as proof that controls operated effectively.
The names sound similar and both are assurance reports.
Fix: Type 1 covers design and implementation at a date only. Only Type 2 tests operating effectiveness over a period.
Ignoring the period covered by the report.
Students focus on the report type and forget the dates.
Fix: Always compare the report period to the client's year. Gaps need extra evidence, such as inquiry and further testing.
Mixing up the user auditor and the service auditor.
Both terms contain 'auditor' and appear together in the standard.
Fix: The user auditor audits the client. The service auditor reports on the service organisation.
Listing generic payroll audit tests only.
Students recognise payroll and drift to wages tests.
Fix: Start with ISA 402 points: understand the service, evaluate the report, then add tests of the client's controls over inputs and outputs.
Worked examples
Example 1
Your audit client, Zeta Co, outsources its payroll to PayServe Ltd. PayServe's auditor has issued a Type 1 report as at 30 June. Zeta's year-end is 31 December. Explain the audit implications and the procedures you would perform.
Show the solution
- Understanding: the user auditor must understand the payroll service and how it affects Zeta's controls and the risk of material misstatement in payroll costs and liabilities.
- Type 1 limits: the report gives evidence on design and implementation at 30 June only. It gives no evidence that controls operated effectively.
- Period: the date is six months before year-end, so there is no evidence for the rest of the year.
- Evaluate the report: assess the service auditor's competence and independence, and whether the controls covered are relevant to Zeta's payroll assertions.
- Further procedures: ask PayServe, via Zeta, for a Type 2 report or for information on changes since 30 June.
- Test Zeta's own controls over payroll inputs, such as approving starters, leavers and pay changes, and review of PayServe's outputs.
- Perform substantive procedures at Zeta, such as reconciling payroll totals to the ledger and tax returns, and analytical review of payroll cost by month.
- If still insufficient evidence, consider visiting PayServe or using another auditor, and consider the effect on the opinion.
Answer: The Type 1 report only supports understanding of design at 30 June. Obtain further evidence through a Type 2 report, tests of Zeta's own controls and substantive procedures. If evidence remains insufficient, consider a modified opinion.
Example 2
State the difference between a Type 1 and a Type 2 report, and explain two factors the user auditor considers before using a Type 2 report.
Show the solution
- Type 1: the service auditor reports on the description of the system and on whether controls are suitably designed and implemented at a specific date.
- Type 2: includes the same, and also reports on whether controls operated effectively over a stated period, with tests performed.
- Factor 1: the service auditor's professional competence and independence from the service organisation.
- Factor 2: whether the period covered and the controls tested are relevant to the user entity's year and risks.
- Link to use: if the period covers only part of the year, additional evidence is needed for the remaining period.
Answer: Type 1 covers design and implementation at a date. Type 2 also covers operating effectiveness over a period. Before relying on a Type 2 report, assess the service auditor's competence and independence, and check the period and controls are relevant to the client.
Exam tips
- Define the roles first when a scenario is long: user entity, user auditor, service organisation, service auditor.
- In Section A or B, an OT asking which report supports reliance on operating effectiveness has one answer: Type 2 covering the relevant period.
- In written answers, always give a fallback procedure at the client, such as reconciliations of outsourced output to the ledger.
- Do not suggest the audit report should refer to the service auditor when the opinion is unmodified. The user auditor takes sole responsibility.
- Match advice to the facts: a short report period, an unknown service auditor or a missing report each lead to a different extra procedure.
Using a Service Organisation's Reports in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Using a Service Organisation's Reports: frequently asked questions
What is the difference between a Type 1 and Type 2 service organisation report?
A Type 1 report covers the description of the system and the design and implementation of controls at one date. A Type 2 report also tests whether controls operated effectively over a period. Only Type 2 gives evidence of operating effectiveness.
Who is the user auditor in ISA 402?
The user auditor is the auditor of the financial statements of the user entity, which is the client that outsources a function. The service auditor is the auditor who reports on the service organisation's controls.
Can I rely on the service organisation's report completely?
No. You must evaluate it first, including the service auditor's competence and independence, the period covered and the relevance of the controls. You may still need further tests of the client's controls or substantive procedures.
What if the client's payroll provider will not give me a report?
You can ask for information, visit the provider, use another auditor or perform substantive procedures on records held by the client. If you still cannot get sufficient appropriate evidence, you consider modifying your opinion.