HKSA 402 - Audit Considerations Relating to Service Organisations (Condensed)
| Section | Key Concept | Brief Description |
|---|---|---|
| Overview & Scope (¶1-5) | Services part of user entity's information system | Services affect flow of information, accounting records, financial reporting, and IT environment; excludes financial institution processing of authorized transactions. |
| Objectives (¶7) | Understand & respond to risks | Obtain understanding of services and their effect on internal control; design audit procedures to address risks of material misstatement. |
| Definitions (¶8) | Key terms | Defines user auditor, service organization, subservice organization, Type 1/2 reports, complementary user entity controls, etc. |
| Understanding Services (¶9-14) | How user entity uses service organization | Understand nature, significance, interaction degree, contractual terms; identify user entity controls; use Type 1/2 reports if needed. |
| Responding to Risks (¶15-17) | Tests of controls & evidence | Determine if evidence from user entity records is sufficient; if not, perform further procedures or obtain Type 2 report for operating effectiveness. |
| Subservice Organizations (¶18) | Carve-out vs. inclusive method | If report excludes subservice organization's controls, apply HKSA 402 to that subservice organization. |
| Fraud & NOCLAR (¶19) | Inquire & evaluate | Inquire about fraud, non-compliance, uncorrected misstatements reported by service organization; evaluate effect on audit procedures. |
| Reporting (¶20-22) | Modified opinion & reference | Modify opinion if insufficient evidence; no reference to service auditor in unmodified opinion unless required by law. |
Overview & Scope (¶1-5)
Scope of HKSA 402
HKSA 402 applies when a user entity uses one or more service organizations. Services are part of the user entity's information system if they affect:
- How information about significant classes of transactions, account balances, and disclosures flows through the system
- Accounting records, specific accounts, and supporting records
- The financial reporting process
- The entity's IT environment
- Financial institutions processing transactions for an entity's account (e.g., bank checking account, broker securities transactions)
- Audit of proprietary financial interests in other entities (partnerships, corporations, joint ventures) when accounted for and reported to interest holders
Effective Date: Periods beginning on or after 15 December 2009.
Objectives (¶7)
User Auditor's Objectives
- Obtain an understanding of the nature and significance of services provided by the service organization and their effect on the user entity's internal control, sufficient to identify and assess risks of material misstatement.
- Design and perform audit procedures responsive to those risks.
Definitions (¶8)
Key Terms
| Term | Definition |
|---|---|
| Complementary user entity controls | Controls that the service organization assumes will be implemented by user entities to achieve control objectives. |
| Type 1 report | Description of system, control objectives, and controls designed and implemented as at a specified date; includes service auditor's opinion on description and suitability of design. |
| Type 2 report | Description of system, control objectives, and controls designed and implemented throughout a period; includes opinion on description, design, and operating effectiveness, plus tests of controls and results. |
| Service auditor | Auditor who provides an assurance report on the service organization's controls. |
| Service organization | Third-party organization that provides services to user entities that are part of their information systems relevant to financial reporting. |
| Subservice organization | A service organization used by another service organization to perform some of the services provided to user entities. |
| User auditor | Auditor who audits the financial statements of a user entity. |
| User entity | Entity that uses a service organization and whose financial statements are being audited. |
Understanding Services Provided (¶9-14)
Obtaining an Understanding
When obtaining an understanding of the user entity, the user auditor shall understand:
- (a) Nature of services and significance – including effect on internal control. Sources: user manuals, contracts, service auditor reports, etc.
- (b) Nature and materiality of transactions – even if immaterial, the nature may require understanding controls.
- (c) Degree of interaction – high interaction allows user entity controls; low interaction may require reliance on service organization controls.
- (d) Nature of relationship – including contractual terms about information, responsibilities, and reports.
Identifying User Entity Controls (¶10)
Identify controls at the user entity that relate to the services provided, including those applied to transactions processed by the service organization. Evaluate their design and implementation.
When Understanding Cannot Be Obtained from User Entity (¶12)
If insufficient understanding, use one or more of:
- Obtain a Type 1 or Type 2 report
- Contact the service organization through the user entity
- Visit the service organization
- Use another auditor to perform procedures
Using Type 1 or Type 2 Reports (¶13-14)
Be satisfied as to the service auditor's competence and independence. Evaluate whether the report's date/period is appropriate. Determine if complementary user entity controls are relevant and implemented.
Responding to Assessed Risks (¶15-17)
Determining Sufficiency of Audit Evidence (¶15)
In responding to assessed risks, the user auditor shall:
- Determine whether sufficient appropriate audit evidence is available from records held at the user entity.
- If not, perform further audit procedures or use another auditor to perform procedures at the service organization.
Tests of Controls (¶16)
When the risk assessment includes an expectation that controls at the service organization are operating effectively, obtain audit evidence from:
- Obtaining a Type 2 report
- Performing tests of controls at the service organization
- Using another auditor to perform tests of controls
Using a Type 2 Report (¶17)
Evaluate whether the report provides sufficient appropriate audit evidence by:
- Checking the date/period of the description and tests
- Determining relevance of complementary user entity controls
- Evaluating the time period covered and time elapsed
- Assessing relevance of tests to financial statement assertions
Subservice Organizations (¶18)
Carve-out vs. Inclusive Method
If the Type 1 or Type 2 report excludes the services of a subservice organization (carve-out method) and those services are relevant to the audit, the user auditor must apply HKSA 402 requirements to the subservice organization.
| Method | Description |
|---|---|
| Inclusive method | Includes the subservice organization's relevant control objectives and related controls in the report. |
| Carve-out method | Excludes the subservice organization's controls; user auditor must obtain evidence separately. |
Fraud, Non-Compliance, and Uncorrected Misstatements (¶19)
Inquiry and Evaluation
The user auditor shall inquire of management of the user entity whether the service organization has reported any fraud, non-compliance with laws and regulations, or uncorrected misstatements affecting the financial statements.
Evaluate how such matters affect the nature, timing, and extent of further audit procedures, including conclusions and the auditor's report.
Reporting by the User Auditor (¶20-22)
Modified Opinion (¶20)
If the user auditor is unable to obtain sufficient appropriate audit evidence regarding the services provided by the service organization, modify the opinion in accordance with HKSA 705 (Revised).
- Unable to obtain sufficient understanding of services
- Unable to obtain evidence about operating effectiveness of controls
- Evidence only available at service organization and no direct access
Reference to Service Auditor (¶21-22)
- Unmodified opinion: Do not refer to the work of a service auditor unless required by law or regulation. If required, indicate that the reference does not diminish the user auditor's responsibility.
- Modified opinion: If reference is relevant to understanding the modification, indicate that it does not diminish the user auditor's responsibility. May refer to the service auditor's report if it helps explain the reason for modification.
❓ Ready to Test?
50 MCQs • 1.25 min each • 62.5 min total
📝 Start Q&A →📚 Full Reference Version🖨️ Save as PDF