Service Organization Implication Flashcards

1
Q

what are substantive procedures

A

used to detect material misstatements during the audit and include
both tests of details and analytical procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is SOC 1

A

reports that provide assurance about a service organization’s controls relevant to user entity’s financial reporting
used by: entity’s auditors for risk assessment
restricted user report: to management of service org’s, user entities and other specified entities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is SOC 2

A

detailed reports that provide assurance about a service organization’s controls over security, availability processing integrity, confidentiality, and privacy of the user entity’s data
used by: clients
restricted user report: to management of service org’s, user entities and other specified entities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what is SOC 3

A

undetailed reports that provide assurance about a service organization’s controls over security, availability processing integrity, confidentiality, and privacy of the user entity’s data
general use report: public use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what is Type 1?

A

address only accuracy of management’s description of the controls AND whether the controls are suitably designed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is Type 2?

A

provide assurance about whether the controls are operating effectively

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Subject matter of System and Organization Controls (SOC) reports for SOC 1 Type 1

A

design of controls relevant to financial reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Subject matter of System and Organization Controls (SOC) reports for SOC 1 Type 2

A

design and operating effectiveness of controls of relevant to financial reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Subject matter of System and Organization Controls (SOC) reports for SOC 2 Type 1

A

design of controls relevant to user’s operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Subject matter of System and Organization Controls (SOC) reports for SOC 2 Type 2

A

design and operating effectiveness of controls relevant to user’s operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOC provides assurance about…

A

the service organization’s internal control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

unmodified opinion

A

able to obtain reasonable assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

disclaimer of opinion

A

unable to obtain reasonable assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

F/S auditor is governed by _______
audits F/S of __________ and gives it to ___________ who relies on ______ for services of ___________

A

SAS; user entities; user organizations; I/C; service organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SOC 1 auditor is governed by _______; examines _____________ of ___________ relevant to users F/S and gives it to ___________

A

SSAE; controls; service organizations; service organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

F/S auditor relies on report of the

A

SOC 1 auditor