Outsourced but Accountable: Service Organizations
Overview
Auditors increasingly face challenges when clients rely on third-party service organizations to process transactions, host systems or manage key aspects of their operations. From payroll and payment processing to e-commerce platforms and inventory services, these arrangements can have a direct impact on financial reporting and audit risk. The auditor must determine the impact of the use of a service organization in planning and performing a quality audit.
This course provides auditors with a practical, hands-on understanding of CAS 402. Participants will learn how to identify when a service organization is relevant to the audit, understand the various types of SOC reports and determine how to obtain sufficient appropriate audit evidence in both risk assessment procedures and risk responses.
Learning Objectives
By the end of the session participants will be able to:
- Appreciate the requirements of CAS 402
- Understand types of service organization reports (Type 1 vs. Type 2)
- Assess the impact of service organizations on risk assessment
- Determine appropriate risk responses
- Apply practical steps to document auditor’s considerations
Course Content
Module 01
Introduction and Overview
Module 02
Service Organization Reports
Module 03
Identifying and Assessing RMM: Information System and Control Activities
Module 04
Identifying and Assessing RMM: Information System and Control Activities
Module 05
Identifying and Assessing RMM: Using SOC Reports
Module 06
Responding to Assessed RMM
Module 07
Concluding and Reporting
Module 08
Bringing It All Together
Module 09
Resources