Skip to content

Advanced Auditing, Assurance and Professional Ethics · Prospective Financial Information and Other Assurance Services

Service Auditor's Report: Intended Users and Purpose (SAE 3402)

Updated 5 October 2026 · Fact-checked

A service auditor's SAE 3402 report is meant only for user entities that use the service organisation and their financial statement auditors. Its purpose is to help them assess risks of material misstatement. It carries a restricted-use statement, because others may misread it. To answer, name the users, the purpose, the restriction and the reason.

Understand Service Auditor's Report: Intended Users and Purpose

Many companies outsource work such as payroll, data hosting or fund administration to a service organisation. The companies that use this service are user entities. Their auditors (user auditors) must understand how the outsourced controls affect the financial statements. Visiting the service organisation for every client is impractical. So one service auditor reports once, and many user auditors rely on that report.

Under SAE 3402 the service auditor gives a Type 1 report (description and suitability of design of controls at a specified date) or a Type 2 report (design plus operating effectiveness over a period). Both cover controls relevant to user entities' internal control over financial reporting.

The report is written for a common purpose. It serves the shared needs of a broad group of user entities and their auditors. It cannot cover the specific facts of each user entity. A reader who does not know the service, the user entity's own controls or the scope of the engagement may draw wrong conclusions. So the report carries a statement that it is intended only for user entities and their auditors, who have enough understanding to consider it along with other information, including the controls the user entities themselves operate. The application guidance around A48 in your study material supports this restriction on use and purpose. Read it once in the standard for the exact wording.

The purpose is narrow: to support user entities and user auditors in assessing the risks of material misstatement of the user entity's financial statements. It is not a general certificate of quality, a guarantee of the service organisation's performance, or an opinion on the user entity's financial statements.

A related point is the subservice organisation, a provider used by the service organisation. In the carve-out method, the description identifies the subservice organisation's services but leaves out its control objectives and controls from the scope. In the inclusive method, the description includes them, and they fall within the service auditor's work. Users must read which method was used. It decides what they can rely on and what extra procedures they need.

Key rules to remember

Intended users
Intended users = user entities + their financial statement auditors
Not the public, not lenders by default, not regulators unless the engagement terms say otherwise.
Purpose of the report
Purpose = help assess risks of material misstatement in user entities' financial statements
The report is not an opinion on the user entity's financial statements.
Restricted-use statement
Report states: intended only for user entities and their auditors who have sufficient understanding to consider it with other information
Includes understanding of controls operated by the user entities themselves.
Type 1 vs Type 2
Type 1 = design at a date; Type 2 = design + operating effectiveness over a period
Only Type 2 gives evidence on operating effectiveness.
Subservice organisation methods
Carve-out = subservice controls excluded; Inclusive = subservice controls included in description and scope
Under carve-out, user auditors must handle those controls separately.

How to solve Service Auditor's Report: Intended Users and Purpose questions

Use this method for any question on who may use the report, why it is restricted, or what the report covers.

  1. 1Identify the roles in the case: service organisation, user entity, user auditor, service auditor, and any subservice organisation.
  2. 2State the intended users: user entities and their financial statement auditors, with sufficient understanding.
  3. 3State the purpose: assessing risks of material misstatement in the user entity's financial statements.
  4. 4Link to the restriction: the report is prepared for a common purpose and may be misread by others, so it carries a restricted-use statement.
  5. 5Check the facts for any unintended reader or purpose, such as a prospective customer, a public circulation or a request to rely for another purpose.
  6. 6Check type and method: Type 1 or Type 2, and carve-out or inclusive for any subservice organisation.
  7. 7Conclude in provision-facts-conclusion form: what the standard says, what the case shows, what the service auditor or user auditor should do.

Quickest way: Users-Purpose-Reason-Scope check

When to use it: For short case MCQs and 4 to 5 mark written answers when time is tight.

  1. Users: is the reader a user entity or its auditor? If not, the report is not meant for them.
  2. Purpose: is the use about risk assessment on financial reporting? If not, it is outside the stated purpose.
  3. Reason: say the report serves common needs and can be misunderstood without context.
  4. Scope: note Type 1 or 2 and carve-out or inclusive before concluding.

Common mistakes in Service Auditor's Report: Intended Users and Purpose

  • Saying anyone who gets the report may rely on it.

    Students treat it like a statutory audit report, which is general-purpose.

    Fix: Remember it is a special-purpose report restricted to user entities and their auditors.

  • Stating the purpose as an opinion on the user entity's financial statements.

    Confusing the service auditor with the user entity's auditor.

    Fix: The service auditor reports on the service organisation's description and controls, not on the user's financial statements.

  • Giving the reason for restriction as confidentiality alone.

    Restriction sounds like a privacy matter.

    Fix: The main reason is the risk of misunderstanding by readers lacking sufficient understanding of the service and related controls.

  • Treating a Type 1 report as evidence of operating effectiveness.

    Both reports look similar and share the same restricted-use statement.

    Fix: Type 1 covers design at a date only. Operating effectiveness needs Type 2.

  • Assuming the carve-out method means the subservice controls are tested by the service auditor.

    Mixing up carve-out with inclusive.

    Fix: Carve-out excludes them from scope. Inclusive brings them into the description and the service auditor's work.

Worked examples

Example 1

A payroll service organisation, Sigma Payroll Ltd, has obtained a Type 2 report from its service auditor. A prospective client asks Sigma to add a line permitting it to rely on the report when deciding whether to sign up. Sigma asks the service auditor whether the report can be changed. Advise.

Show the solution
  1. Provision: the report is for user entities and their auditors, with a statement restricting use to them.
  2. Facts: the prospective client is not yet a user entity and its auditor has no financial statements affected by Sigma's controls.
  3. Facts: the report serves common needs of existing users and may be misunderstood by a reader without enough understanding of the service and related controls.
  4. Conclusion: the service auditor should not add a line extending reliance to the prospective client without evaluating the engagement terms and the standard's requirements. The restricted-use statement stays, and a prospective client's decision is outside the stated purpose.

Answer: The service auditor should not extend the report's use as requested. The report is intended for user entities and their auditors to assess risks of material misstatement, and the restricted-use statement should remain.

Example 2

Delta Ltd uses Omega Data Services for transaction processing. Omega hosts its servers with Zeta Cloud, a subservice organisation. Omega's Type 2 report uses the carve-out method for Zeta. Delta's auditor wants to use the report to assess risks of material misstatement. Explain what the auditor can use the report for and what remains to be done.

Show the solution
  1. Users and purpose: Delta is a user entity and its auditor is a user auditor. Using the report to assess risks of material misstatement is within the intended purpose.
  2. Type 2 gives evidence on design and operating effectiveness of Omega's controls over the period covered.
  3. Carve-out: Zeta's services are identified, but Zeta's control objectives and controls are outside the description and the service auditor's work.
  4. Therefore the report gives no assurance on Zeta's controls.
  5. Next steps: the user auditor should consider how Zeta's controls affect Delta's financial statements and obtain other evidence, such as a report on Zeta or procedures at Delta or Omega, as needed.

Answer: Delta's auditor may use Omega's Type 2 report for its intended purpose of risk assessment for Omega's controls. Because of carve-out, it gives no assurance on Zeta's controls, so the auditor must get other evidence for those.

Exam tips

  • Write the restriction in two parts: who the users are, and why others are excluded. Examiners reward the reason.
  • In a case, underline any reader who is not a user entity or user auditor, such as a prospective client, a lender or a regulator.
  • Name the report type and subservice method in your answer. These are easy marks in case MCQs.
  • Do not quote A48 by wording. Say the application guidance supports the restriction on use and the stated purpose.
  • Close with a one-line conclusion telling the service auditor or user auditor what to do.

Practice questions from Prospective Financial Information and Other Assurance Services

Service Auditor's Report: Intended Users and Purpose: frequently asked questions

Who can use a service auditor's report under SAE 3402?

The intended users are the user entities of the service organisation and their financial statement auditors. They should have enough understanding of the service and related controls to consider the report with other information.

Why is the report restricted in use?

It is prepared for the common needs of a broad group of users and cannot address each user's specifics. Readers without enough understanding may misinterpret it, so the report states it is intended only for user entities and their auditors.

What is the purpose of the service auditor's report?

It helps user entities and their auditors assess the risks of material misstatement in the user entities' financial statements. It is not an opinion on those statements.

What is the difference between carve-out and inclusive methods?

Under carve-out, the description identifies the subservice organisation's services but excludes its controls from scope. Under inclusive, the subservice organisation's relevant control objectives and controls are included in the description and in the service auditor's work.