A mid-size manufacturer outsources payroll. Wages, withholdings, direct deposits, W-2s: all of it lives at the processor. The auditor never sets foot in the processor's data center, yet the audit opinion still covers payroll expense. AU-C 402 exists because the gap between "we outsourced it" and "we still own the financial statements" is where audits fail.
Outsourced services touch the financial statements through their inputs and outputs. Payroll runs flow into wage expense; custodians produce holdings lists that drive investment balances. The auditor must obtain sufficient appropriate evidence about those processes. "We don't run that system" is not an audit answer.
KEY: The user auditor's opinion covers the entire financial statements, including amounts produced by service organizations. A SOC 1® report is one source of evidence, not a substitute for the user auditor's judgment.
HIGH-FREQUENCY: AU-C 402 separates two roles. The user auditor audits the user entity (the client). The service auditor examines controls at the service organization (the outsourcer). The service auditor never opines on the user entity's statements.
Common mistakes
- Treating a Type 1 as if it tested operating effectiveness. Type 1 is design only at a point in time. A Type 1 with no exceptions tells you the controls were designed properly that day, nothing about the year.
- Ignoring the date mismatch on a Type 2. A Type 2 covering October 1 through September 30 does not cover a December 31 calendar-year audit. Trap: "rely on the report", which is wrong because three months are unaddressed.
- Skipping CUEC testing. The auditor reads the SOC report, notes the CUECs, but never tests whether the user entity performs them. The exam plants a clean Type 2 alongside a CUEC the client clearly does not perform ("rarely reviews," "occasionally skipped"). Correct answer: substantive procedures because the CUEC is not operating.
Bottom line
- The user auditor remains responsible for the audit opinion even when controls live at a service organization (AU-C 402); outsourcing the process does not outsource the audit
- SOC 1 Type 1 covers design at a point in time; Type 2 covers design AND operating effectiveness over a period (typically 6-12 months) and is the only report that lets you reduce substantive testing
- Carve-out method excludes subservice organization controls; inclusive method incorporates them, so under carve-out the user auditor needs separate evidence about the subservice org
- Complementary user entity controls (CUECs) are controls the service organization assumes the client performs; if the client does not perform them, the SOC report's conclusions do not transfer
Exam shortcut
When a question hands you a SOC report, scan for four things in order: type (1 or 2), period vs. audit period, opinion (qualified or unqualified), and CUEC list. If any breaks, you cannot rely on the report. Memory aid: "Type 2, Time aligned, Unqualified opinion, Tested CUECs": the four T's of SOC reliance. Miss one T, increase the testing.
The full lesson (about 2,462 words, 16 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- II.C4
Browse all free CPA AUD lessons or jump into free CPA AUD practice questions.