Skip to content

ACCA Strategic Professional · Advanced Audit and Assurance (International) · Other current issues

During the audit of Corvus Bank, a firm's cloud service provider suffers an outage and a data breach exposing client files from several audit engagements, including Corvus Bank's. The engagement partner is considering the firm's obligations. Which combination of responses is most consistent with ISQM 1, the IESBA Code and ISA 260?

The firm remains responsible under ISQM 1 for risks from technology and service providers, so it should respond within its quality management system, protect confidentiality under the IESBA Code, and communicate with the affected client and those charged with governance. Destroying files or ignoring the breach is inappropriate.

  1. ATake no action because the cloud provider, not the firm, is responsible for security
  2. BRespond under the firm's quality management system by addressing the technology and service provider risk, protect confidentiality, and communicate with the client and those charged with governance in line with legal and ethical requirementsCorrect
  3. CDestroy the affected working papers to prevent further exposure
  4. DDisclose the breach only to the firm's other clients, not to Corvus Bank

Explanation

ISQM 1 requires the firm to identify and respond to quality risks, including those from technological resources and service providers. The IESBA Code's confidentiality principle and applicable law require suitable safeguards and disclosure where appropriate. Communication with those charged with governance is also appropriate where the breach affects the client. Destroying working papers breaches retention requirements, and outsourcing does not remove the firm's responsibility.

Did you get it right without looking?

One question tells you little. A timed set on Other current issues shows your real accuracy, how long you take and where you lose marks.

More Other current issues questions