📄 PDF — HKICPA Handbook Vol III (Code of Ethics)

PDF viewer not supported.

🎥 Video Lesson (Coming Soon)
🎬HKSA 402 - Audit Considerations Relating to Service Organisations walkthrough video coming soon.

HKSA 402 - Audit Considerations Relating to Service Organisations

Ad Space
Ad Space
Ad Space

Overview and Scope

HKSA 402 deals with the user auditor's responsibility to obtain sufficient appropriate audit evidence when a user entity uses the services of one or more service organizations. This standard expands on how the user auditor applies HKSA 315 (Revised 2019) and HKSA 330 in obtaining an understanding of the user entity, including the entity's system of internal control relevant to financial statement preparation.

Scope (Paragraphs 1-5)

Many entities outsource aspects of their business to organizations that provide services ranging from performing specific tasks under entity direction to replacing entire business units or functions (e.g., tax compliance function). Services provided by a service organization are relevant to the audit when those services, and the controls over them, are part of the user entity's information system relevant to financial statement preparation.

Services are part of a user entity's information system if they affect:

  • How information relating to significant classes of transactions, account balances, and disclosures flows through the user entity's information system
  • The accounting records, specific accounts, and other supporting records
  • The financial reporting process used to prepare financial statements
  • The entity's IT environment relevant to the above
  • Exclusions from HKSA 402:

  • Services provided by financial institutions limited to processing transactions for an entity's account held at the financial institution (e.g., checking account transactions by a bank, securities transactions by a broker)
  • Audit of transactions arising from proprietary financial interests in other entities (partnerships, corporations, joint ventures) when proprietary interests are accounted for and reported to interest holders
  • Effective Date (Paragraph 6)

    Effective for audits of financial statements for periods beginning on or after 15 December 2009.

    Ad Space

    Objectives (Paragraph 7)

    The objectives of the user auditor are:

  • To obtain an understanding of the nature and significance of the services provided by the service organization and their effect on the user entity's system of internal control, sufficient to provide an appropriate basis for identification and assessment of risks of material misstatement
  • To design and perform audit procedures responsive to those risks
  • Ad Space

    Definitions (Paragraph 8)

    TermDefinition
    Complementary user entity controlsControls that the service organization assumes, in the design of its service, will be implemented by user entities, and which, if necessary to achieve control objectives, are identified in the description of its system
    Type 1 reportA report comprising: (i) a description by management of the service organization's system, control objectives and related controls designed and implemented as at a specified date; and (ii) a service auditor's report with reasonable assurance opinion on the description and suitability of design of controls
    Type 2 reportA report comprising: (i) a description by management of the service organization's system, control objectives and related controls, their design and implementation as at a specified date or throughout a specified period and, in some cases, their operating effectiveness throughout a specified period; and (ii) a service auditor's report with reasonable assurance opinion on description, suitability of design, and operating effectiveness, including description of tests of controls and results
    Service auditorAn auditor who, at the request of the service organization, provides an assurance report on the controls of a service organization
    Service organizationA third-party organization (or segment) that provides services to user entities that are part of those entities' information systems relevant to financial reporting
    Service organization's systemThe policies and procedures designed, implemented and maintained by the service organization to provide user entities with the services covered by the service auditor's report
    Subservice organizationA service organization used by another service organization to perform some of the services provided to user entities that are part of those user entities' information systems relevant to financial reporting
    User auditorAn auditor who audits and reports on the financial statements of a user entity
    User entityAn entity that uses a service organization and whose financial statements are being audited

    Ad Space

    Requirements

    Obtaining an Understanding of the Services Provided by a Service Organization, Including Internal Control (Paragraphs 9-14)

    Paragraph 9 - Understanding How User Entity Uses Service Organization

    When obtaining an understanding of the user entity in accordance with HKSA 315 (Revised 2019), the user auditor shall obtain an understanding of how a user entity uses the services of a service organization in the user entity's operations, including:

    (a) The nature of the services provided and their significance to the user entity, including effect on internal control

    Sources of information (A1-A2):

  • User manuals
  • System overviews
  • Technical manuals
  • Contract or service level agreement
  • Reports by service organizations, internal audit function or regulatory authorities
  • Reports by the service auditor, including management letters
  • Knowledge from the user auditor's experience with the service organization
  • Examples of relevant services (A3-A4):

  • Bank trust departments that invest and service assets for employee benefit plans
  • Mortgage bankers that service mortgages for others
  • Application service providers providing packaged software applications and technology environment
  • Maintenance of accounting records
  • Management of assets
  • Initiating, recording or processing transactions as agent
  • Smaller entities may use external bookkeeping services, but this does not relieve management of their responsibilities for financial statements (A5).

    (b) The nature and materiality of transactions processed or accounts or financial reporting processes affected

    The significance of controls depends on the nature of services, including nature and materiality of transactions processed. Even if transactions appear immaterial, the nature may be significant enough to require understanding of controls (A6).

    (c) The degree of interaction between the activities of the service organization and those of the user entity

    High degree of interaction: User entity authorizes transactions, service organization processes and accounts for them. User entity may implement effective controls (A7).

    Low degree of interaction: Service organization initiates, records, processes, and accounts for transactions. User entity may rely on controls at the service organization (A7).

    (d) The nature of the relationship between the user entity and the service organization, including relevant contractual terms

    Contract or service level agreement may provide for (A8):

  • Information to be provided and responsibilities for initiating transactions
  • Application of regulatory requirements
  • Indemnification for performance failure
  • Whether the service organization will provide a type 1 or type 2 report
  • Rights of access to accounting records
  • Whether agreement allows direct communication between user auditor and service auditor
  • Paragraph 10 - Identifying Controls at User Entity

    When obtaining an understanding of the entity's system of internal control, the user auditor shall identify controls in the control activities component at the user entity, from those that relate to the services provided by the service organization, including those applied to transactions processed by the service organization, and evaluate their design and determine whether they have been implemented.

    Examples of user entity controls (A12-A13):

  • Comparing data submitted to service organization with reports received after processing
  • Recomputing a sample of payroll amounts for clerical accuracy
  • Reviewing total payroll amount for reasonableness
  • Paragraph 11 - Determining Sufficiency of Understanding

    The user auditor shall determine whether a sufficient understanding has been obtained to provide an appropriate basis for identification and assessment of risks of material misstatement.

    Paragraph 12 - Procedures When Understanding Cannot Be Obtained from User Entity

    If the user auditor is unable to obtain a sufficient understanding from the user entity, the user auditor shall obtain that understanding from one or more of the following procedures:

    (a) Obtaining a type 1 or type 2 report, if available

    Type 1 or type 2 reports may be issued under HKSAE 3402 or under standards established by an authorized standards setting organization (may be identified as Type A or Type B reports) (A16).

    (b) Contacting the service organization, through the user entity, to obtain specific information

    (c) Visiting the service organization and performing procedures that will provide the necessary information

    (d) Using another auditor to perform procedures that will provide the necessary information about controls at the service organization

    Factors influencing the decision (A15):

  • Size of both entities
  • Complexity of transactions and services
  • Location of service organization
  • Whether the procedure is expected to effectively provide sufficient appropriate audit evidence
  • Nature of the relationship
  • Paragraphs 13-14 - Using a Type 1 or Type 2 Report

    Paragraph 13 - Determining Sufficiency and Appropriateness

    The user auditor shall be satisfied as to:

  • The service auditor's professional competence and independence from the service organization
  • The adequacy of the standards under which the type 1 or type 2 report was issued
  • The user auditor may make inquiries about the service auditor to the service auditor's professional organization or other practitioners and inquire whether the service auditor is subject to regulatory oversight (A21).

    Paragraph 14 - Planning to Use Type 1 or Type 2 Report

    If the user auditor plans to use a type 1 or type 2 report as audit evidence to support understanding about design and implementation of controls at the service organization, the user auditor shall:

    (a) Evaluate whether the description and design of controls is at a date or for a period appropriate for the user auditor's purposes

    (b) Evaluate the sufficiency and appropriateness of the evidence provided by the report for understanding of controls

    (c) Determine whether complementary user entity controls identified by the service organization are relevant to the user entity and, if so, obtain an understanding of whether the user entity has designed and implemented such controls

    A type 1 or type 2 report may assist in understanding (A22):

  • Aspects of controls at the service organization that may affect processing of transactions
  • Flow of significant transactions through the service organization
  • Control objectives relevant to financial statement assertions
  • Whether controls are suitably designed and implemented
  • A type 1 report does not provide any evidence of operating effectiveness of controls (A22).

    If the report is as of a date or for a period outside the reporting period, the user auditor may perform procedures to update the information (A23):

  • Discussing changes with user entity personnel
  • Reviewing current documentation and correspondence
  • Discussing changes with service organization personnel
  • Responding to the Assessed Risks of Material Misstatement (Paragraphs 15-17)

    Paragraph 15 - Determining Sufficiency of Audit Evidence

    In responding to assessed risks, the user auditor shall:

    (a) Determine whether sufficient appropriate audit evidence concerning relevant financial statement assertions is available from records held at the user entity; and, if not,

    (b) Perform further audit procedures to obtain sufficient appropriate audit evidence or use another auditor to perform those procedures at the service organization on the user auditor's behalf

    Considerations (A24-A28):

    The use of a service organization may increase or decrease risk of material misstatement. If the user entity lacks expertise or resources, using a service organization may decrease risk.

    When the service organization maintains material elements of accounting records, direct access may be necessary (A25):

  • Physical inspection of records at service organization's premises
  • Interrogation of records maintained electronically
  • Procedures for obtaining evidence about balances/assets held by service organization (A26):

  • Inspecting records and documents held by the user entity
  • Inspecting records and documents held by the service organization
  • Obtaining confirmations of balances and transactions from the service organization
  • Performing analytical procedures on records maintained by the user entity or reports from the service organization
  • Paragraph 16 - Tests of Controls

    When the user auditor's risk assessment includes an expectation that controls at the service organization are operating effectively, the user auditor shall obtain audit evidence about the operating effectiveness of those controls from one or more of the following procedures:

    (a) Obtaining a type 2 report, if available

    (b) Performing appropriate tests of controls at the service organization

    (c) Using another auditor to perform tests of controls at the service organization on behalf of the user auditor

    This requirement applies when (A29):

  • The user auditor intends to rely on the operating effectiveness of controls at the service organization in determining the nature, timing and extent of substantive procedures
  • Substantive procedures alone, or in combination with tests of controls at the user entity, cannot provide sufficient appropriate audit evidence at the assertion level
  • If a type 2 report is not available, the user auditor may (A30):

  • Contact the service organization through the user entity to request a type 2 report
  • Use another auditor to perform tests of controls
  • Visit the service organization and perform tests of controls if the service organization agrees
  • Paragraph 17 - Using a Type 2 Report as Audit Evidence

    If the user auditor plans to use a type 2 report as audit evidence that controls at the service organization are operating effectively, the user auditor shall determine whether the service auditor's report provides sufficient appropriate audit evidence by:

    (a) Evaluating whether the description, design and operating effectiveness of controls is at a date or for a period appropriate for the user auditor's purposes

    (b) Determining whether complementary user entity controls identified by the service organization are relevant to the user entity and, if so, obtaining an understanding of whether the user entity has designed and implemented such controls and, if so, testing their operating effectiveness

    (c) Evaluating the adequacy of the time period covered by the tests of controls and the time elapsed since the performance of the tests of controls

    (d) Evaluating whether the tests of controls performed by the service auditor and the results thereof are relevant to the assertions in the user entity's financial statements and provide sufficient appropriate audit evidence to support the user auditor's risk assessment

    Factors to consider (A31):

  • Time period covered by tests of controls and time elapsed since performance
  • Scope of the service auditor's work and services/processes covered
  • Results of tests of controls and the service auditor's opinion
  • Additional considerations (A32-A38):

  • The shorter the period covered and the longer the time elapsed, the less audit evidence the test may provide
  • If there is little overlap between the type 2 report period and the period for which the user auditor intends to rely, the report offers less audit evidence
  • Additional evidence may be needed about significant changes to controls outside the period covered
  • If the service auditor's testing period is completely outside the user entity's financial reporting period, the user auditor cannot rely on such tests unless other procedures are performed
  • Exceptions noted by the service auditor or a modified opinion do not automatically mean the report is not useful
  • Communication of deficiencies (A39):

    The user auditor shall communicate in writing significant deficiencies identified during the audit to both management and those charged with governance. Matters to communicate include:

  • Controls within the entity's process to monitor internal control that could be implemented
  • Instances where complementary user entity controls are noted but not implemented
  • Controls needed at the service organization that do not appear to have been implemented
  • Type 1 and Type 2 Reports that Exclude the Services of a Subservice Organization (Paragraph 18)

    If the user auditor plans to use a type 1 or type 2 report that excludes the services provided by a subservice organization and those services are relevant to the audit, the user auditor shall apply the requirements of this HKSA with respect to the services provided by the subservice organization.

    Two methods of reporting (A40):

  • Inclusive method: Includes the subservice organization's relevant control objectives and related controls
  • Carve-out method: Excludes the subservice organization's controls
  • If the carve-out method is used and the subservice organization's services are relevant, the user auditor must apply HKSA 402 requirements to the subservice organization.

    Fraud, Non-Compliance with Laws and Regulations, and Uncorrected Misstatements (Paragraph 19)

    The user auditor shall inquire of management of the user entity whether the service organization has reported to the user entity, or whether the user entity is otherwise aware of, any fraud, non-compliance with laws and regulations or uncorrected misstatements affecting the financial statements of the user entity.

    The user auditor shall evaluate how such matters affect the nature, timing and extent of the user auditor's further audit procedures, including the effect on the user auditor's conclusions and user auditor's report.

    A service organization may be required under contract to disclose to affected user entities any fraud, non-compliance or uncorrected misstatements attributable to the service organization's management or employees (A41).

    Reporting by the User Auditor (Paragraphs 20-22)

    Paragraph 20 - Modified Opinion

    The user auditor shall modify the opinion in the user auditor's report in accordance with HKSA 705 (Revised) if the user auditor is unable to obtain sufficient appropriate audit evidence regarding the services provided by the service organization relevant to the audit.

    Circumstances leading to scope limitation (A42):

  • Unable to obtain sufficient understanding of services provided by the service organization
  • Risk assessment includes expectation that controls are operating effectively but unable to obtain sufficient appropriate audit evidence about operating effectiveness
  • Sufficient appropriate audit evidence only available from records held at the service organization and unable to obtain direct access
  • Whether the user auditor expresses a qualified opinion or disclaims an opinion depends on whether the possible effects are material or pervasive.

    Paragraph 21 - Reference to Service Auditor in Unmodified Opinion

    The user auditor shall not refer to the work of a service auditor in the user auditor's report containing an unmodified opinion unless required by law or regulation to do so. If such reference is required, the user auditor's report shall indicate that the reference does not diminish the user auditor's responsibility for the audit opinion.

    Paragraph 22 - Reference to Service Auditor in Modified Opinion

    If reference to the work of a service auditor is relevant to an understanding of a modification to the user auditor's opinion, the user auditor's report shall indicate that such reference does not diminish the user auditor's responsibility for that opinion.

    The user auditor does not make reference to the service auditor's report as a basis, in part, for the user auditor's opinion. However, when expressing a modified opinion because of a modified opinion in a service auditor's report, the user auditor is not precluded from referring to the service auditor's report if such reference assists in explaining the reason for the modified opinion (A44).

    Conformity and Compliance with International Standards on Auditing (Paragraph 23)

    As of March 2025, this HKSA conforms with International Standard on Auditing (ISA) 402, Audit Considerations Relating to an Entity Using a Service Organization. Compliance with the requirements of this HKSA ensures compliance with ISA 402.

    Ad Space

    Key Takeaways Summary Table

    AreaKey Requirement
    Understanding servicesObtain understanding of nature, significance, interaction degree, and contractual terms
    Controls identificationIdentify and evaluate user entity controls related to service organization services
    Insufficient understandingUse type 1/2 report, contact service organization, visit, or use another auditor
    Type 1/2 report useEvaluate competence/independence of service auditor, adequacy of standards, appropriateness of period
    Responding to risksDetermine if evidence available from user entity records; if not, perform further procedures
    Tests of controlsObtain type 2 report, perform tests, or use another auditor when relying on controls
    Subservice organizationsApply HKSA 402 requirements if carve-out method used and services are relevant
    Fraud/NOCLARInquire of management, evaluate effect on procedures
    ReportingModify opinion if insufficient evidence; no reference to service auditor in unmodified opinion unless required

    Ad Space

    ---

    ❓ Ready to Test Your Knowledge?

    50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).

    📝 Start Q&A →🖨️ Save as PDF