S4-m4 Flashcards
The service auditor, when auditing the service organization, is required to:
-establish, prior to acceptance of the SOC engagement, and understanding with service organization management about its responsibilities of the service auditor
-communication with the management of the service org
-determine the appropriate persons within the service organizations management or governance structure with whom to interact
The objectives of the service auditor are to:
obtain reasonable assurance about whether, in all material respects, based on suitable criteria:
-managements description of the service organization system fairly presents the system that was designed and implemented
- the control related to the control objectives stated were suitably designed
-when included in the scope, the controls operated effectively
-report in accordance with the service auditors findings
During planning of any SOC engagement, the service auditor is responsible for:
-determining whether to accept or continue the engagement
-agreeing on engagement terms
-reaching an understanding with management regarding a written assertion
During planning of a SOC 1 engagement, the service auditor is also responsible for:
-assessing the risk of material misstatement
-obtaining an understanding of the service orgs system and assessing the suitability of the criteria used by management in preparing its system description
During planning of a SOC 2 & 3 engagement, the service auditor is also responsible for:
-establishing an overall strategy for the engagement; sets scope timing, direction
-performing risk assessment procedures; how system controls were designed, implemented, and operated to provide reasonable assurance
Agreed upon engagement terms
Service auditor and service organization
-objectives and scope
-responsibilities of the service auditor and the responsible party, including the responsibility o management to provide a representation letter
-identification of the criteria used to measure, evaluate, or disclose information about the subject matter
-acknowledgment that the engagement will be conducted in accordance with attestation standards established
Service Organization and Service Auditor
Independence Considertations
the service auditor needs to be independent with respect to the responsible party. The responsible party is most often the service organization
Subservice Organization and Service Auditor
Independence Considertations
If management elects to use the inclusive method, then the subservice organization management is a responsible party and should be independent of the service auditor
What should the service auditor d when they lack independence?
when the service auditor is required by law to accept the engagement the service auditor should disclaim an opinion and should specifically state the service auditor is not independent
The service auditors consideration of materiality should include…
SOC 1
the fair presentation of the description of the service organizations system
Fair presentation of the description relates to…
The concept of materiality
the information being reported on, not the financial statements of user entities
Materiality relates to…
SOC 1
qualitative factors, such as whether significant aspects of the processing have been included in the description or if relevant information has been omitted or distorted
Quantitative factors
Materiallity with respect to SOC 1 T 2
The tolerable and observed rate of deviations
Qualitative factors
Materiallity with respect to SOC 1 T 2
The nature and cause of deviations
Materiality can be described as:
SOC 2
- the likelihood and magnitude of the risks that threaten the achievement of the service organizations service commitments and system requirements
-whether the controls the service organization has designed, implemented, and operated were effective in mitigating those risks to an acceptable level based on the applicable trust services criteria