📝 Condensed VersionKey points only 📚 Full Reference →
📄 PDF — HKICPA Handbook Vol III

PDF viewer not supported.

🎥 Video Lesson (Coming Soon)
🎬Video walkthrough coming soon.
SectionKey ConceptBrief Description
Overview & Scope (¶1-5)Services part of user entity's information systemServices affect flow of information, accounting records, financial reporting, and IT environment; excludes financial institution processing of authorized transactions.
Objectives (¶7)Understand & respond to risksObtain understanding of services and their effect on internal control; design audit procedures to address risks of material misstatement.
Definitions (¶8)Key termsDefines user auditor, service organization, subservice organization, Type 1/2 reports, complementary user entity controls, etc.
Understanding Services (¶9-14)How user entity uses service organizationUnderstand nature, significance, interaction degree, contractual terms; identify user entity controls; use Type 1/2 reports if needed.
Responding to Risks (¶15-17)Tests of controls & evidenceDetermine if evidence from user entity records is sufficient; if not, perform further procedures or obtain Type 2 report for operating effectiveness.
Subservice Organizations (¶18)Carve-out vs. inclusive methodIf report excludes subservice organization's controls, apply HKSA 402 to that subservice organization.
Fraud & NOCLAR (¶19)Inquire & evaluateInquire about fraud, non-compliance, uncorrected misstatements reported by service organization; evaluate effect on audit procedures.
Reporting (¶20-22)Modified opinion & referenceModify opinion if insufficient evidence; no reference to service auditor in unmodified opinion unless required by law.
Ad Space

Overview & Scope (¶1-5)

Scope of HKSA 402

HKSA 402 applies when a user entity uses one or more service organizations. Services are part of the user entity's information system if they affect:

  • How information about significant classes of transactions, account balances, and disclosures flows through the system
  • Accounting records, specific accounts, and supporting records
  • The financial reporting process
  • The entity's IT environment
Exclusions:
  • Financial institutions processing transactions for an entity's account (e.g., bank checking account, broker securities transactions)
  • Audit of proprietary financial interests in other entities (partnerships, corporations, joint ventures) when accounted for and reported to interest holders

Effective Date: Periods beginning on or after 15 December 2009.

Ad Space

Objectives (¶7)

User Auditor's Objectives

  1. Obtain an understanding of the nature and significance of services provided by the service organization and their effect on the user entity's internal control, sufficient to identify and assess risks of material misstatement.
  2. Design and perform audit procedures responsive to those risks.
Ad Space

Definitions (¶8)

Key Terms

TermDefinition
Complementary user entity controlsControls that the service organization assumes will be implemented by user entities to achieve control objectives.
Type 1 reportDescription of system, control objectives, and controls designed and implemented as at a specified date; includes service auditor's opinion on description and suitability of design.
Type 2 reportDescription of system, control objectives, and controls designed and implemented throughout a period; includes opinion on description, design, and operating effectiveness, plus tests of controls and results.
Service auditorAuditor who provides an assurance report on the service organization's controls.
Service organizationThird-party organization that provides services to user entities that are part of their information systems relevant to financial reporting.
Subservice organizationA service organization used by another service organization to perform some of the services provided to user entities.
User auditorAuditor who audits the financial statements of a user entity.
User entityEntity that uses a service organization and whose financial statements are being audited.
Ad Space

Understanding Services Provided (¶9-14)

Obtaining an Understanding

When obtaining an understanding of the user entity, the user auditor shall understand:

  • (a) Nature of services and significance – including effect on internal control. Sources: user manuals, contracts, service auditor reports, etc.
  • (b) Nature and materiality of transactions – even if immaterial, the nature may require understanding controls.
  • (c) Degree of interaction – high interaction allows user entity controls; low interaction may require reliance on service organization controls.
  • (d) Nature of relationship – including contractual terms about information, responsibilities, and reports.

Identifying User Entity Controls (¶10)

Identify controls at the user entity that relate to the services provided, including those applied to transactions processed by the service organization. Evaluate their design and implementation.

When Understanding Cannot Be Obtained from User Entity (¶12)

If insufficient understanding, use one or more of:

  • Obtain a Type 1 or Type 2 report
  • Contact the service organization through the user entity
  • Visit the service organization
  • Use another auditor to perform procedures

Using Type 1 or Type 2 Reports (¶13-14)

Be satisfied as to the service auditor's competence and independence. Evaluate whether the report's date/period is appropriate. Determine if complementary user entity controls are relevant and implemented.

Note: A Type 1 report does not provide evidence of operating effectiveness of controls.
Ad Space

Responding to Assessed Risks (¶15-17)

Determining Sufficiency of Audit Evidence (¶15)

In responding to assessed risks, the user auditor shall:

  • Determine whether sufficient appropriate audit evidence is available from records held at the user entity.
  • If not, perform further audit procedures or use another auditor to perform procedures at the service organization.

Tests of Controls (¶16)

When the risk assessment includes an expectation that controls at the service organization are operating effectively, obtain audit evidence from:

  • Obtaining a Type 2 report
  • Performing tests of controls at the service organization
  • Using another auditor to perform tests of controls

Using a Type 2 Report (¶17)

Evaluate whether the report provides sufficient appropriate audit evidence by:

  • Checking the date/period of the description and tests
  • Determining relevance of complementary user entity controls
  • Evaluating the time period covered and time elapsed
  • Assessing relevance of tests to financial statement assertions
Communication of deficiencies: Communicate significant deficiencies in writing to management and those charged with governance, including controls that could be implemented or are missing.
Ad Space

Subservice Organizations (¶18)

Carve-out vs. Inclusive Method

If the Type 1 or Type 2 report excludes the services of a subservice organization (carve-out method) and those services are relevant to the audit, the user auditor must apply HKSA 402 requirements to the subservice organization.

MethodDescription
Inclusive methodIncludes the subservice organization's relevant control objectives and related controls in the report.
Carve-out methodExcludes the subservice organization's controls; user auditor must obtain evidence separately.
Ad Space

Fraud, Non-Compliance, and Uncorrected Misstatements (¶19)

Inquiry and Evaluation

The user auditor shall inquire of management of the user entity whether the service organization has reported any fraud, non-compliance with laws and regulations, or uncorrected misstatements affecting the financial statements.

Evaluate how such matters affect the nature, timing, and extent of further audit procedures, including conclusions and the auditor's report.

Ad Space

Reporting by the User Auditor (¶20-22)

Modified Opinion (¶20)

If the user auditor is unable to obtain sufficient appropriate audit evidence regarding the services provided by the service organization, modify the opinion in accordance with HKSA 705 (Revised).

Scope limitation examples:
  • Unable to obtain sufficient understanding of services
  • Unable to obtain evidence about operating effectiveness of controls
  • Evidence only available at service organization and no direct access

Reference to Service Auditor (¶21-22)

  • Unmodified opinion: Do not refer to the work of a service auditor unless required by law or regulation. If required, indicate that the reference does not diminish the user auditor's responsibility.
  • Modified opinion: If reference is relevant to understanding the modification, indicate that it does not diminish the user auditor's responsibility. May refer to the service auditor's report if it helps explain the reason for modification.

❓ Ready to Test?

50 MCQs • 1.25 min each • 62.5 min total

📝 Start Q&A →📚 Full Reference Version🖨️ Save as PDF