Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

Rohan Ltd outsources its payroll processing to a cloud service provider. The auditor of Rohan Ltd obtains a Type 2 service auditor's report covering 1 April to 31 December, while the financial year ends 31 March. The report has no exceptions, but lists complementary user entity controls that Rohan Ltd should implement. What should the user auditor do?

The user auditor should obtain further evidence for the uncovered period from 1 January to 31 March and test whether Rohan Ltd has implemented the complementary user entity controls. A clean partial-period report is not enough, and the auditor cannot share responsibility by referring to the service auditor.

  1. AAccept the report as sufficient for the entire year since it has no exceptions
  2. BDisregard the report because the service organisation is not part of the entity
  3. CObtain additional evidence for the gap period of 1 January to 31 March and test whether Rohan Ltd has implemented the complementary user entity controlsCorrect
  4. DRefer to the service auditor's work in the audit report to share responsibility

Explanation

A Type 2 report covering only part of the year leaves a gap, so the user auditor needs additional evidence such as inquiries or updated testing for the remaining period. The complementary user entity controls must also be tested at Rohan. Using the report does not reduce the user auditor's sole responsibility for the opinion, so no reference should be made in the report.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions