Outsourcing payroll, accounting, loan processing, cloud applications or transaction processing does not outsource the auditor’s responsibility. When a service provider forms part of the client’s information system relevant to financial reporting, SA 402 requires the user auditor to understand how those outsourced services affect the audit and to respond to the resulting risks.
When does SA 402 become relevant?
SA 402, Audit Considerations Relating to an Entity Using a Service Organisation, applies when a user entity uses services from another organisation and those services are relevant to the audit of the user entity’s financial statements. The key question is therefore not simply whether the client has outsourced something. The question is whether the outsourced activity and its controls affect financial reporting, relevant assertions, or the auditor’s risk assessment.
Examples can include outsourced payroll processing, transaction processing, accounting operations, hosted financial applications and other arrangements where the service organisation processes or maintains information that feeds the financial statements. ICAI’s current standards repository lists SA 402 within the risk-assessment and response series. The full standard is available in ICAI’s SA 402 text, while the ICAI standards repository provides the broader standards framework.
What the auditor should understand first
The auditor should map the outsourced process before deciding what evidence is needed. A useful starting point is to identify the nature of the services, the significance of transactions or balances processed by the service organisation, the degree of interaction between the client and the provider, relevant contractual terms, and the controls that remain with the client.
This distinction matters because outsourcing rarely removes all controls from the user entity. Management may still approve master-data changes, reconcile reports, review exception files, authorise payments or monitor service-level outputs. Those user-side controls may be central to the audit approach.
Practical process-mapping checklist
- Identify the flow: What data leaves the entity, what does the provider do with it, and what comes back?
- Identify financial-statement impact: Which balances, transaction classes, disclosures and assertions are affected?
- Identify interfaces: How is data transferred between the client and provider, and how are interface failures detected?
- Identify user controls: Which controls must the client perform for the outsourced process to work reliably?
- Identify provider evidence: Is an assurance report on the provider’s controls available, and does it cover the relevant period, systems and control objectives?
Type 1 and Type 2 reports are not interchangeable
SA 402 distinguishes between reports that address the description and design of controls and reports that also address operating effectiveness over a period. That difference affects how much reliance an auditor can potentially place on the report. A report should never be treated as a generic certificate that automatically solves the audit of an outsourced process.
The user auditor should read the scope carefully: the service organisation covered, systems included, period covered, control objectives, exceptions, the service auditor’s opinion, and any complementary user-entity controls. A report covering the wrong system or an incomplete period may have limited relevance even if it is otherwise well prepared.
How to respond when evidence from the provider is insufficient
If the auditor cannot obtain a sufficient understanding from the user entity, SA 402 contemplates additional routes, which may include obtaining a suitable service-auditor report, contacting the service organisation through the user entity, visiting the service organisation and performing relevant procedures, or using another auditor to perform procedures that provide the necessary information. The appropriate route depends on risk, materiality, access and the nature of the outsourced process.
The core audit principle remains unchanged: the auditor needs sufficient appropriate audit evidence. A vendor contract, management statement or dashboard may help understanding, but it does not automatically provide evidence about the design or operating effectiveness of relevant controls.
Worked example: outsourced payroll
Assume a company sends employee master data and monthly variable-pay inputs to a payroll processor. The processor calculates payroll and returns a payroll register and payment file. The company’s finance team reconciles the register to HR records and the general ledger, while authorised personnel approve the payment file.
The auditor should not merely note that payroll is outsourced. The audit file should explain the end-to-end flow, identify who can change employee master data, test relevant user controls such as reconciliations and approvals, understand controls at the processor that matter to payroll assertions, and evaluate any assurance report used as evidence. If the assurance report requires the client to operate specified complementary controls, the auditor should consider whether those controls actually operated at the client.
Common mistakes in SA 402 audits
- Assuming that outsourcing transfers management’s financial-reporting responsibility to the vendor.
- Collecting a service-organisation report without checking its scope, period or relevance.
- Ignoring complementary controls that the user entity is expected to perform.
- Failing to map data interfaces between the client and the service provider.
- Treating a Type 1 report as evidence of operating effectiveness over a period.
- Documenting the vendor arrangement but not linking it to assertions, risks and audit responses.
What should the audit working papers show?
A review-ready file should make the logic visible: why the outsourced service is relevant, what understanding was obtained, which financial-statement areas are affected, what risks were identified, what controls exist at the user entity and service organisation, what reports or other evidence were evaluated, what exceptions were found, and how the auditor concluded that the planned response was sufficient.
ICAI has also discussed SA 402 in the context of outsourced accounting software and audit-trail responsibilities, noting that auditors may need to consider independent assurance reports on service organisations and document the understanding, procedures and conclusions. See ICAI’s audit-trail guidance discussion for that practical context.
Practical takeaway
For SA 402, start with the transaction flow rather than the vendor’s certificate. Determine what the provider actually does, what the client must still control, which assertions are affected, and what evidence is needed. Then evaluate service-auditor reports as one part of that evidence—not as a substitute for understanding the outsourced process and designing an appropriate audit response.