M5 Reporting on Controls at a Service organization Flashcards

1
Q

What is a service organization?

A

an outside organization used by an entity to process some portion of their accounting transactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Service organization controls =

A

user entity’s information system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SOC1

A

Reports on internal control over financial reporting (ICFR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SOC2

A

Intended to give assurance to a broad range of users regarding the controls in place at a service organization:
Security
Availability
Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Type 1 Report

A

Reports on the design and implementation of a service organizations controls (not operating effectiveness)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Type 2 Report

A

Report on the design, implementation, and operating effectiveness of a service organizations controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Service auditor responsibilities include

A

-Read the other information to identify any material inconsistencies or misstatements
-Include a description of the scope and nature of the auditor’s procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

User auditor responsibilities:

A

Make inquiries regarding the professional reputation of the service auditor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which SOC report is restricted

A

Both

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When should you include management’s description of the service organization’s system.

A

In a Type 1 or Type 2 Attestation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly