AU-C Section 402 sets out the audit considerations that apply when an entity uses a service organization, and it puts one obligation at the center: the user auditor must obtain enough evidence about the service organization’s controls to assess control risk and support an opinion on the user entity’s financial statements.1American Institute of Certified Public Accountants. AU-C Section 9402 – Audit Considerations Relating to an Entity Using a Service Organization Everything else in the standard—SOC reports, complementary controls, subservice providers, reporting language—flows from that requirement.
When AU-C 402 Applies
The standard is triggered when a client outsources services that touch its financial transactions in a meaningful way. If the outside provider initiates, records, processes, or reports transactions flowing into the client’s financial statements, AU-C 402 is in scope.1American Institute of Certified Public Accountants. AU-C Section 9402 – Audit Considerations Relating to an Entity Using a Service Organization Payroll processors, investment custodians, claims administrators, and managed hosting providers are common examples.
Purely administrative arrangements—janitorial services, standard utility provision—are outside the scope. The working test: would the client’s financial statements risk material misstatement without reliance on the provider’s controls? If yes, AU-C 402 applies. And responsibility does not shift with the outsourcing: the client retains ultimate responsibility for its internal control over financial reporting, and the user auditor bears sole responsibility for the opinion.
Understanding the Service Organization
The first task is to understand how the outsourced work connects to the audit. That means identifying which financial statement assertions are affected—completeness, existence, valuation, and so on—because those answers shape scoping and testing decisions that follow.
Several sources typically feed that understanding. The contract between the client and provider is the natural starting point; it defines responsibilities and control expectations. Discussions with client personnel fill in how data flows between the two organizations and what monitoring the client performs over the outsourced function. System descriptions, control manuals, and prior-period assurance reports from the service organization round out the operational picture.
Using a SOC Report as Evidence
The primary way a user auditor gains assurance over a service organization’s controls is through a Service Organization Control report. A SOC 1 report focuses specifically on controls relevant to user entities’ internal control over financial reporting, which makes it the report most directly tied to AU-C 402.2AICPA & CIMA. Employee Benefit Plans: SOC 1 Reports and Service Organizations Resource Center It is prepared by an independent service auditor engaged by the service organization for the benefit of its customers and their auditors.
Type 1 Versus Type 2
A Type 1 report describes the service organization’s system and evaluates the design of its controls as of a single date. It answers whether the controls are suitably designed. It says nothing about whether those controls actually worked over time, and it is generally not enough on its own to support a reduction in the assessed level of control risk.2AICPA & CIMA. Employee Benefit Plans: SOC 1 Reports and Service Organizations Resource Center
A Type 2 report covers everything in a Type 1 and adds tests of operating effectiveness over a defined period. That evidence of controls functioning throughout the reporting window is what typically allows a user auditor to reduce the scope of substantive testing at the user entity level.2AICPA & CIMA. Employee Benefit Plans: SOC 1 Reports and Service Organizations Resource Center
Whichever report is provided, the user auditor should confirm that the controls tested actually map to the assertions at risk in the client’s audit. A report covering dozens of control objectives is not useful if none of them address the assertions affected by the outsourced function.
SOC 2 Reports
User auditors sometimes encounter SOC 2 reports, which cover security, availability, processing integrity, confidentiality, or privacy rather than financial reporting controls specifically. AICPA Interpretation No. 1 of AU-C Section 402 addresses whether and how a user auditor may use a SOC 2 report in a financial statement audit.3AICPA & CIMA. Interpretation No. 1 of AU-C Section 402 A SOC 2 may carry useful information, but the user auditor has to evaluate whether the trust service criteria covered align with control objectives relevant to internal control over financial reporting, and extra analysis is needed to identify complementary user entity controls and other financial-reporting-relevant controls.1American Institute of Certified Public Accountants. AU-C Section 9402 – Audit Considerations Relating to an Entity Using a Service Organization
Evaluating the Service Auditor’s Report
Receiving a SOC 1 Type 2 report does not end the work. AU-C 402 requires independent evaluation before determining how much reliance to place on it.
Start with the service auditor. The user auditor evaluates the service auditor’s professional competence and independence, typically by reviewing qualifications and reputation. If objectivity is in doubt, the report is unreliable as audit evidence.
Then look at timing. The SOC report must cover the period under audit for the client. If the report period ends several months before fiscal year-end, a gap exists that cannot be assumed away. Bridging procedures may include inquiries of the service organization about significant changes since the report date, reviewing interim communications, or performing additional testing at the client level to cover the uncovered window. The longer the gap, the more work is required.
Exceptions and deviations in the testing results each need evaluation. Not every exception undermines the related control objective, but each one has to be assessed on its own terms. If the service auditor issued a qualified, adverse, or disclaimer opinion, the user auditor cannot rely on the affected controls and must treat that lack of assurance as a control deficiency. Two paths remain:
- Request permission to perform tests of controls directly at the service organization’s location. This provides stronger evidence but is costly and requires the service organization’s cooperation.
- Expand substantive procedures at the user entity to compensate by testing the underlying data more aggressively.
Either way, more work is required. There is no shortcut when the SOC report falls short.
Complementary User Entity Controls
One area that catches user auditors off guard is complementary user entity controls, commonly called CUECs. These are specific controls that the service organization’s system is designed to rely on the client to implement and operate. The service organization builds its system assuming those CUECs are in place.
A payroll processor, for example, might assume the client will independently review and approve each payroll run before it is finalized. If the client never performs that review, a link in the control chain is broken. The user auditor must confirm that CUECs are both properly designed and actually operating at the client. Skipping this step means the user auditor cannot rely on the service organization’s broader control structure, regardless of how clean the SOC report looks.1American Institute of Certified Public Accountants. AU-C Section 9402 – Audit Considerations Relating to an Entity Using a Service Organization
Subservice Organizations
Service organizations often outsource part of their own operations to another provider, known as a subservice organization. A payroll processor might use a separate cloud infrastructure provider to host its systems. That adds a layer, because controls relevant to the client’s financial reporting may sit at the subservice organization rather than the primary provider.
Under the inclusive method, the subservice organization’s controls are folded into the service organization’s SOC report. The service auditor’s examination covers both, giving the user auditor a more complete picture in a single document.
Under the carve-out method, the subservice organization’s controls are excluded from the SOC report’s scope. The report acknowledges the subservice organization and describes what it does but does not test its controls. This is the more common approach in practice. When carve-out is used, the user auditor must treat the subservice organization much like an additional service organization and apply AU-C 402 to those services as well, which typically means obtaining a separate SOC report for the subservice organization or performing alternative procedures. How much additional work is needed depends on how significant the subservice functions are to the client’s financial reporting.
Effect on the User Auditor’s Opinion
When the user auditor has obtained sufficient evidence about the service organization’s controls, the use of a service organization generally has no effect on the audit opinion itself. The user auditor issues an unmodified opinion and should not reference the service organization or the service auditor’s report in that opinion.4U.S. Government Accountability Office. Financial Audit Manual Volume 2 Mentioning the service auditor could imply a division of responsibility, when in fact the user auditor bears sole responsibility for the opinion on the client’s financial statements.
The exception arises when sufficient evidence cannot be obtained and the gap is material. Then the user auditor must issue a modified opinion, qualified or adverse depending on severity. If the service auditor’s report is referenced in the basis for modification, the language must make clear that the reference is not a basis for sharing responsibility. The user auditor’s opinion stands on its own, and the basis for modification section must explain how the control failure or lack of evidence affected the ability to opine.