Requirements
ASAE 3000
10
The service auditor shall not represent compliance with this ASAE unless the service auditor has complied with the requirements of this ASAE and ASAE 3000.
Ethical Requirements
11
[Deleted by the AUASB. Refer Aus 11.1.]
See ASA 102.
Management and Those Charged with Governance
12
Where this ASAE requires the service auditor to enquire of, request representations from, communicate with, or otherwise interact with the service organisation, the service auditor shall determine the appropriate person(s) within the service organisation’s management or governance structure with whom to interact. This shall include consideration of which person(s) have the appropriate responsibilities for and knowledge of the matters concerned. (Ref: Para. A6)
Acceptance and Continuance
13
Before agreeing to accept, or continue, an engagement, the service auditor shall:
- Determine whether:
- The service auditor has the capabilities and competence to perform the engagement; (Ref: Para. A7)
- The criteria the assurance practitioner expects to be applied by the service organisation to prepare the description of its system are suitable and will be available to user entities and their auditors; and
- The scope of the engagement and the service organisation’s description of its system will not be so limited that they are unlikely to be useful to user entities and their auditors.
- Obtain the agreement of the service organisation that it acknowledges and understands its responsibility:
- For the preparation of the description of its system, and accompanying service organisation’s statement, including the completeness, accuracy and method of presentation of that description and statement; (Ref: Para. A8)
- To have a reasonable basis for the service organisation’s statement accompanying the description of its system; (Ref: Para. A9)
- For stating in the service organisation’s statement the criteria it used to prepare the description of its system;
- For stating in the description of its system:
- The control objectives; and,
- Where they are specified by law or regulation, or another party (for example, a user group or a professional body), the party who specified them;
- For identifying the risks that threaten achievement of the control objectives stated in the description of its system, and designing and implementing controls to provide reasonable assurance that those risks will not prevent achievement of the control objectives stated in the description of its system, and therefore that the stated control objectives will be achieved; and (Ref: Para. A10)
- To provide the service auditor with:
- Access to all information, such as records, documentation and other matters, including service level agreements, of which the service organisation is aware that is relevant to the description of the service organisation’s system and the accompanying service organisation’s statement;
- Additional information that the service auditor may request from the service organisation for the purpose of the assurance engagement; and
- Unrestricted access to persons within the service organisation from whom the service auditor determines it necessary to obtain evidence.
Acceptance of a Change in the Terms of the Engagement
14
If the service organisation requests a change in the scope of the engagement before the completion of the engagement, the service auditor shall be satisfied that there is a reasonable justification for the change. (Ref: Para. A11‑Aus A12.1)
Determining the Suitability of the Criteria
15
The service auditor shall determine whether the service organisation has used suitable criteria in preparing the description of its system, in evaluating whether controls are suitably designed, and, in the case of a type 2 report, in evaluating whether controls are operating effectively.*
See ASAE 3000, paragraph 41.
16
In determining the suitability of the criteria to evaluate the service organisation’s description of its system, the service auditor shall determine if the criteria encompass, at a minimum:
- Whether the description presents how the service organisation’s system was designed and implemented, including, as appropriate:
- The types of services provided, including, as appropriate, classes of transactions processed;
- The procedures, within both information technology and manual systems, by which services are provided, including, as appropriate, procedures by which transactions are initiated, recorded, processed, corrected as necessary, and transferred to the reports and other information prepared for user entities;
- The related records and supporting information, including, as appropriate, accounting records, supporting information and specific accounts that are used to initiate, record, process and report transactions; this includes the correction of incorrect information and how information is transferred to the reports and other information prepared for user entities;
- How the service organisation’s system deals with significant events and conditions, other than transactions;
- The process used to prepare reports and other information for user entities;
- The specified control objectives and controls designed to achieve those objectives;
- Complementary user entity controls contemplated in the design of the controls; and
- Other aspects of the service organisation’s control environment, risk assessment process, information system (including the related business processes) and communication, control activities and monitoring controls that are relevant to the services provided. (Ref: Para. A15)
- In the case of a type 2 report, whether the description includes relevant details of changes to the service organisation’s system during the period covered by the description.
- Whether the description omits or distorts information relevant to the scope of the service organisation’s system being described, while acknowledging that the description is prepared to meet the common needs of a broad range of user entities and their auditors and may not, therefore, include every aspect of the service organisation’s system that each individual user entity and its auditor may consider important in its particular environment.
17
In determining the suitability of the criteria to evaluate the design of controls, the service auditor shall determine if the criteria encompass, at a minimum, whether:
- The service organisation has identified the risks that threaten achievement of the control objectives stated in the description of its system; and
- The controls identified in that description would, if operated as described, provide reasonable assurance that those risks do not prevent the stated control objectives from being achieved.
18
In determining the suitability of the criteria to evaluate the operating effectiveness of controls in providing reasonable assurance that the stated control objectives identified in the description will be achieved, the service auditor shall determine if the criteria encompass, at a minimum, whether the controls were consistently applied as designed throughout the specified period. This includes whether manual controls were applied by individuals who have the appropriate competence and authority. (Ref: Para. A13‑A14)
Materiality
19
When planning and performing the engagement, the service auditor shall consider materiality with respect to the fair presentation of the description, the suitability of the design of controls and, in the case of a type 2 report, the operating effectiveness of controls. (Ref: Para. A16‑A18)
Obtaining an Understanding of the Service Organisation’s System
20
The service auditor shall obtain an understanding of the service organisation’s system, including controls that are included in the scope of the engagement. (Ref: Para. A19‑A20)
Obtaining Evidence Regarding the Description
21
The service auditor shall obtain and read the service organisation’s description of its system, and shall evaluate whether those aspects of the description included in the scope of the engagement are fairly presented, including whether: (Ref: Para. A21‑A22)
- Control objectives stated in the service organisation’s description of its system are reasonable in the circumstances; (Ref: Para. A23)
- Controls identified in that description were implemented;
- Complementary user entity controls, if any, are adequately described; and
- Services performed by a subservice organisation, if any, are adequately described, including whether the inclusive method or the carve‑out method has been used in relation to them.
22
The service auditor shall determine, through other procedures in combination with enquiries, whether the service organisation’s system has been implemented. Those other procedures shall include observation, and inspection of records and other documentation, of the manner in which the service organisation’s system operates and controls are applied. (Ref: Para. A24)
Obtaining Evidence Regarding Design of Controls
23
The service auditor shall determine which of the controls at the service organisation are necessary to achieve the control objectives stated in the service organisation’s description of its system, and shall assess whether those controls were suitably designed. This determination shall include: (Ref: Para. A25‑A27)
- Identifying the risks that threaten the achievement of the control objectives stated in the service organisation’s description of its system; and
- Evaluating the linkage of controls identified in the service organisation’s description of its system with those risks.
Obtaining Evidence Regarding Operating Effectiveness of Controls
24
When providing a type 2 report, the service auditor shall test those controls that the service auditor has determined are necessary to achieve the control objectives stated in the service organisation’s description of its system, and assess their operating effectiveness throughout the period. Evidence obtained in prior engagements about the satisfactory operation of controls in prior periods does not provide a basis for a reduction in testing, even if it is supplemented with evidence obtained during the current period. (Ref: Para. A28‑A32)
25
When designing and performing tests of controls, the service auditor shall:
- Perform other procedures in combination with enquiry to obtain evidence about:
- How the control was applied;
- The consistency with which the control was applied; and
- By whom or by what means the control was applied;
- Determine whether controls to be tested depend upon other controls (indirect controls) and, if so, whether it is necessary to obtain evidence supporting the operating effectiveness of those indirect controls; and (Ref: Para. A33‑A34)
- Determine means of selecting items for testing that are effective in meeting the objectives of the procedure. (Ref: Para. A35‑A36)
26
When determining the extent of tests of controls, the service auditor shall consider matters including the characteristics of the population to be tested, which includes the nature of controls, the frequency of their application (for example, monthly, daily, a number of times per day), and the expected rate of deviation.
Sampling
27
When the service auditor uses sampling, the service auditor shall: (Ref: Para. A35‑A36)
- Consider the purpose of the procedure and the characteristics of the population from which the sample will be drawn when designing the sample;
- Determine a sample size sufficient to reduce sampling risk to an appropriately low level;
- Select items for the sample in such a way that each sampling unit in the population has a chance of selection;
- If a designed procedure is not applicable to a selected item, perform the procedure on a replacement item; and
- If unable to apply the designed procedures, or suitable alternative procedures, to a selected item, treat that item as a deviation.
Nature and Cause of Deviations
28
The service auditor shall investigate the nature and cause of any deviations identified and shall determine whether:
- Identified deviations are within the expected rate of deviation and are acceptable; therefore, the testing that has been performed provides an appropriate basis for concluding that the control is operating effectively throughout the specified period;
- Additional testing of the control or of other controls is necessary to reach a conclusion on whether the controls relative to a particular control objective are operating effectively throughout the specified period; or (Ref: Para. A25)
- The testing that has been performed provides an appropriate basis for concluding that the control did not operate effectively throughout the specified period.
29
In the extremely rare circumstances when the service auditor considers a deviation discovered in a sample to be an anomaly and no other deviations have been identified that cause the service auditor to conclude that the relevant control is not operating effectively throughout the specified period, the service auditor shall obtain a high degree of certainty that such deviation is not representative of the population. The service auditor shall obtain this degree of certainty by performing additional procedures to obtain sufficient appropriate evidence that the deviation does not affect the remainder of the population.
The Work of an Internal Audit Function
[8]Obtaining an Understanding of the Internal Audit Function
[Footnote deleted by the AUASB. Refer paragraph Aus 30.1.]
30
If the service organisation has an internal audit function, the service auditor shall obtain an understanding of the nature of the responsibilities of the internal audit function and of the activities performed in order to determine whether the internal audit function is likely to be relevant to the engagement. (Ref: Para. A37)
Aus 30.1
This ASAE does not deal with instances when individual internal auditors provide direct assistance to the service auditor in carrying out assurance procedures.
Determining Whether and to What Extent to Use the Work of the Internal Auditors
31
The service auditor shall determine:
- Whether the work of the internal auditors is likely to be adequate for purposes of the engagement; and
- If so, the planned effect of the work of the internal auditors on the nature, timing or extent of the service auditor’s procedures.
32
In determining whether the work of the internal auditors is likely to be adequate for purposes of the engagement, the service auditor shall evaluate:
- The objectivity of the internal audit function;
- The technical competence of the internal auditors;
- Whether the work of the internal auditors is likely to be carried out with due professional care; and
- Whether there is likely to be effective communication between the internal auditors and the service auditor.
33
In determining the planned effect of the work of the internal auditors on the nature, timing or extent of the service auditor’s procedures, the service auditor shall consider: (Ref: Para. A38)
- The nature and scope of specific work performed, or to be performed, by the internal auditors;
- The significance of that work to the service auditor’s conclusions; and
- The degree of subjectivity involved in the evaluation of the evidence gathered in support of those conclusions.
Using the Work of the Internal Audit Function
34
In order for the service auditor to use specific work of the internal auditors, the service auditor shall evaluate and perform procedures on that work to determine its adequacy for the service auditor’s purposes. (Ref: Para. A39)
35
To determine the adequacy of specific work performed by the internal auditors for the service auditor’s purposes, the service auditor shall evaluate whether:
- The work was performed by internal auditors having adequate technical training and proficiency;
- The work was properly supervised, reviewed and documented;
- Adequate evidence has been obtained to enable the internal auditors to draw reasonable conclusions;
- Conclusions reached are appropriate in the circumstances and any reports prepared by the internal auditors are consistent with the results of the work performed; and
- Exceptions relevant to the engagement or unusual matters disclosed by the internal auditors are properly resolved.
Effect on the Service Auditor’s Assurance Report
36
If the work of the internal audit function has been used, the service auditor shall make no reference to that work in the section of the service auditor’s assurance report that contains the service auditor’s opinion. (Ref: Para. A40)
37
In the case of a type 2 report, if the work of the internal audit function has been used in performing tests of controls, that part of the service auditor’s assurance report that describes the service auditor’s tests of controls and the results thereof shall include a description of the internal auditor’s work and of the service auditor’s procedures with respect to that work. (Ref: Para. A41)
Written Representations
38
The service auditor shall request the service organisation to provide written representations: (Ref: Para. A42)
- That reaffirm the statement accompanying the description of the system;
- That it has provided the service auditor with all relevant information and access agreed to;[9] and
- That it has disclosed to the service auditor any of the following of which it is aware:
- Non‑compliance with law and regulation, fraud, or uncorrected deviations attributable to the service organisation that may affect one or more user entities;
- Design deficiencies in controls;
- Instances where controls have not operated as described; and
- Any events subsequent to the period covered by the service organisation’s description of its system up to the date of the service auditor’s assurance report that could have a significant effect on the service auditor’s assurance report.
See paragraph 13(b)(vi) of this ASAE.
39
The written representations shall be in the form of a representation letter addressed to the service auditor.*. The date of the written representations shall be as near as practicable to, but not after, the date of the service auditor’s assurance report.
An example representation letter is included in [Aus] Appendix 0B.
Other Information
41
The service auditor shall read the other information, if any, included in a document containing the service organisation’s description of its system and the service auditor’s assurance report, to identify material inconsistencies, if any, with that description. While reading the other information for the purpose of identifying material inconsistencies, the service auditor may become aware of an apparent misstatement of fact in that other information.
42
If the service auditor identifies a material inconsistency or becomes aware of an apparent misstatement of fact in the other information, the service auditor shall discuss the matter with the service organisation. If the service auditor concludes that there is a material inconsistency or a misstatement of fact in the other information that the service organisation refuses to correct, the service auditor shall take further appropriate action. (Ref: Para. A44‑A45)
Subsequent Events
43
The service auditor shall enquire whether the service organisation is aware of any events subsequent to the period covered by the service organisation’s description of its system up to the date of the service auditor’s assurance report that may have caused the service auditor to amend the assurance report. If the service auditor is aware of such an event, and information about that event is not disclosed by the service organisation, the service auditor shall disclose it in the service auditor’s assurance report.
44
The service auditor has no obligation to perform any procedures regarding the description of the service organisation’s system, or the suitability of design or operating effectiveness of controls, after the date of the service auditor’s assurance report.
Documentation
45
The service auditor shall prepare, on a timely basis, engagement documentation that provides a record of the basis for the assurance report that is sufficient and appropriate to enable an experienced service auditor, having no previous connection with the engagement, to understand:
- The nature, timing, and extent of the procedures performed to comply with this ASAE and applicable legal and regulatory requirements;
- The results of the procedures performed, and the evidence obtained; and
- Significant matters arising during the engagement, and the conclusions reached thereon and significant professional judgements made in reaching those conclusions.
46
In documenting the nature, timing and extent of procedures performed, the service auditor shall record:
- The identifying characteristics of the specific items or matters being tested;
- Who performed the work and the date such work was completed; and
- Who reviewed the work performed and the date and extent of such review.
47
If the service auditor uses specific work of the internal auditors, the service auditor shall document the conclusions reached regarding the evaluation of the adequacy of the work of the internal auditors, and the procedures performed by the service auditor on that work.
48
The service auditor shall document discussions of significant matters with the service organisation and others including the nature of the significant matters discussed and when and with whom the discussions took place.
49
If the service auditor has identified information that is inconsistent with the service auditor’s final conclusion regarding a significant matter, the service auditor shall document how the service auditor addressed the inconsistency.
50
The service auditor shall assemble the documentation in an engagement file and complete the administrative process of assembling the final engagement file on a timely basis after the date of the service auditor’s assurance report.[10]
Paragraphs A54-A55 of ASQC 1 provide further guidance.
51
After the assembly of the final engagement file has been completed, the service auditor shall not delete or discard documentation before the end of its retention period. (Ref: Para. A46)
52
If the service auditor finds it necessary to modify existing engagement documentation or add new documentation after the assembly of the final engagement file has been completed and that documentation does not affect the service auditor’s report, the service auditor shall, regardless of the nature of the modifications or additions, document:
- The specific reasons for making them; and
- When and by whom they were made and reviewed.
Preparing the Service Auditor’s Assurance Report
Content of the Service Auditor’s Assurance Report
53
The service auditor’s assurance report shall include, at a minimum, the following basic elements: (Ref: Para. A47)
- A title that clearly indicates the report is an independent service auditor’s assurance report.
- An addressee.
- Identification of:
- The service organisation’s description of its system, and the service organisation’s statement, which includes the matters described in paragraph 9(k)(ii) of this ASAE for a type 2 report, or paragraph 9(j)(ii) of this ASAE for a type 1 report.
- Those parts of the service organisation’s description of its system, if any, that are not covered by the service auditor’s opinion.
- If the description refers to the need for complementary user entity controls, a statement that the service auditor has not evaluated the suitability of design or operating effectiveness of complementary user entity controls, and that the control objectives stated in the service organisation’s description of its system can be achieved only if complementary user entity controls are suitably designed or operating effectively, along with the controls at the service organisation.
- If services are performed by a subservice organisation, the nature of activities performed by the subservice organisation as described in the service organisation’s description of its system and whether the inclusive method or the carve‑out method has been used in relation to them. Where the carve‑out method has been used, a statement that the service organisation’s description of its system excludes the control objectives and related controls at relevant subservice organisations, and that the service auditor’s procedures do not extend to controls at the subservice organisation. Where the inclusive method has been used, a statement that the service organisation’s description of its system includes control objectives and related controls at the subservice organisation, and that the service auditor’s procedures extended to controls at the subservice organisation.
- Identification of the applicable criteria, and the party specifying the control objectives.
- A statement that the report and, in the case of a type 2 report, the description of tests of controls are intended only for user entities and their auditors, who have a sufficient understanding to consider it, along with other information including information about controls operated by user entities themselves, when assessing the risks of material misstatements of user entities’ financial reports/statements. (Ref: Para. A48)
- A statement that the service organisation is responsible for:
- Preparing the description of its system, and the accompanying statement, including the completeness, accuracy and method of presentation of that description and that statement;
- Providing the services covered by the service organisation’s description of its system;
- Stating the control objectives (where not identified by law or regulation, or another party, for example, a user group or a professional body); and
- Designing and implementing controls to achieve the control objectives stated in the service organisation’s description of its system.
- A statement that the service auditor’s responsibility is to express an opinion on the service organisation’s description, on the design of controls related to the control objectives stated in that description and, in the case of a type 2 report, on the operating effectiveness of those controls, based on the service auditor’s procedures.
- [Deleted by the AUASB. Refer Aus 53.1(h).]
Aus 53.1(h)
A statement that the firm of which the assurance practitioner is a member applies ASQC 1.
53(i)
[Deleted by the AUASB. Refer Aus 53.2(i).]
Aus 53.2(i)
A statement that the assurance practitioner complies with the independence and other ethical requirements related to assurance engagements.*
53
- A statement that the engagement was performed in accordance with ASAE 3402 Assurance Reports on Controls at a Service Organisation, which requires that the service auditor plan and perform procedures to obtain reasonable assurance about whether, in all material respects, the service organisation’s description of its system is fairly presented and the controls are suitably designed and, in the case of a type 2 report, are operating effectively.
- A summary of the service auditor’s procedures to obtain reasonable assurance and a statement of the service auditor’s belief that the evidence obtained is sufficient and appropriate to provide a basis for the service auditor’s opinion, and, in the case of a type 1 report, a statement that the service auditor has not performed any procedures regarding the operating effectiveness of controls and therefore no opinion is expressed thereon.
- A statement of the limitations of controls and, in the case of a type 2 report, of the risk of projecting to future periods any evaluation of the operating effectiveness of controls.
- The service auditor’s opinion, expressed in the positive form, on whether, in all material respects, based on suitable criteria:
- In the case of a type 2 report:
- The description fairly presents the service organisation’s system that had been designed and implemented throughout the specified period;
- The controls related to the control objectives stated in the service organisation’s description of its system were suitably designed throughout the specified period; and
- The controls tested, which were those necessary to provide reasonable assurance that the control objectives stated in the description were achieved, operated effectively throughout the specified period.
- In the case of a type 1 report:
- The description fairly presents the service organisation’s system that had been designed and implemented as at the specified date; and
- The controls related to the control objectives stated in the service organisation’s description of its system were suitably designed as at the specified date.
- In the case of a type 2 report:
- The date of the service auditor’s assurance report, which shall be no earlier than the date on which the service auditor has obtained the evidence on which the service auditor’s opinion is based.
- The name of the service auditor, and the location in the jurisdiction where the service auditor practices.
See ASA 102.
54
In the case of a type 2 report, the service auditor’s assurance report shall include a separate section after the opinion, or an attachment, that describes the tests of controls that were performed and the results of those tests. In describing the tests of controls, the service auditor shall clearly state which controls were tested, identify whether the items tested represent all or a selection of the items in the population, and indicate the nature of the tests in sufficient detail to enable user auditors to determine the effect of such tests on their risk assessments. If deviations have been identified, the service auditor shall include the extent of testing performed that led to identification of the deviations (including the sample size where sampling has been used), and the number and nature of the deviations noted. The service auditor shall report deviations even if, on the basis of tests performed, the service auditor has concluded that the related control objective was achieved. (Ref: Para. A18 and A49)
Modified Opinions
55
If the service auditor concludes that: (Ref: Para. A50‑A52)
- The service organisation’s description does not fairly present, in all material respects, the system as designed and implemented;
- The controls related to the control objectives stated in the description were not suitably designed, in all material respects;
- In the case of a type 2 report, the controls tested, which were those necessary to provide reasonable assurance that the control objectives stated in the service organisation’s description of its system were achieved, did not operate effectively, in all material respects; or
- The service auditor is unable to obtain sufficient appropriate evidence,
the service auditor’s opinion shall be modified, and the service auditor’s assurance report shall include a section with a clear description of all the reasons for the modification.
Other Communication Responsibilities
56
If the service auditor becomes aware of non‑compliance with laws and regulations, fraud, or uncorrected errors attributable to the service organisation that are not clearly trivial and may affect one or more user entities, the service auditor shall determine whether the matter has been communicated appropriately to affected user entities. If the matter has not been so communicated and the service organisation is unwilling to do so, the service auditor shall take appropriate action. (Ref: Para. A53)