Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

An audit client has migrated its sales system to a cloud-based SaaS platform managed by a third-party service provider. The provider has issued a Type 2 SOC 1 report (SA 402 context) covering the previous nine months of the financial year. The auditor intends to rely on the provider's controls over revenue processing. What is the most appropriate auditor action?

The auditor should evaluate the report's scope, period and the service auditor's competence, consider complementary user entity controls, and gather additional evidence for the three uncovered months. A Type 2 report helps, but SA 402 requires sufficient appropriate evidence for the whole period of reliance.

  1. ARely on the report fully, since a Type 2 report covers operating effectiveness and the remaining three months need no attention
  2. BIgnore the report because the auditor cannot rely on controls operated by an outside party
  3. CAsk the service provider to cancel the report and issue a Type 1 report to cover the whole year
  4. DEvaluate the report's scope, the service auditor's competence, and obtain additional evidence for the uncovered three months, along with considering complementary user entity controlsCorrect

Explanation

SA 402 requires the user auditor to assess whether the report gives sufficient appropriate evidence about the relevant period. A gap of three months needs additional procedures, such as inquiries or testing, and the client's own user controls must be considered. Option A ignores the gap in the period covered.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions