Outsourced but Accountable: Service Organizations

Overview

Auditors increasingly face challenges when clients rely on third-party service organizations to process transactions, host systems or manage key aspects of their operations. From payroll and payment processing to e-commerce platforms and inventory services, these arrangements can have a direct impact on financial reporting and audit risk. The auditor must determine the impact of the use of a service organization in planning and performing a quality audit.

This course provides auditors with a practical, hands-on understanding of CAS 402. Participants will learn how to identify when a service organization is relevant to the audit, understand the various types of SOC reports and determine how to obtain sufficient appropriate audit evidence in both risk assessment procedures and risk responses.

 

Learning Objectives

By the end of the session participants will be able to:

  • Appreciate the requirements of CAS 402
  • Understand types of service organization reports (Type 1 vs. Type 2)
  • Assess the impact of service organizations on risk assessment
  • Determine appropriate risk responses
  • Apply practical steps to document auditor’s considerations

Course Content

Module 01

Introduction and Overview

Module 02

Service Organization Reports

Module 03

Identifying and Assessing RMM: Information System and Control Activities

Module 04

Identifying and Assessing RMM: Information System and Control Activities

Module 05

Identifying and Assessing RMM: Using SOC Reports

Module 06

Responding to Assessed RMM

Module 07

Concluding and Reporting

Module 08

Bringing It All Together

Module 09

Resources

← Back to Professional Development Courses