When a company outsources payroll, cloud accounting, transaction processing or another finance-related process, the statutory auditor cannot treat the outsourced activity as a black box. SA 402, Audit Considerations Relating to an Entity Using a Service Organisation, requires the user auditor to understand how the outsourced service affects financial reporting, assess related risks of material misstatement and design audit procedures that respond to those risks. The practical challenge is knowing what evidence a service-auditor report actually gives, and when a Type 1 report is not enough.
When does SA 402 become relevant?
SA 402 is relevant when services provided by a third-party service organisation form part of the user entity’s information system relevant to financial reporting. ICAI’s official SA 402 text explains that outsourced activities can range from a specific task to an entire business function. The key question is whether the service affects significant transaction classes, accounting records, financial-reporting processes or related controls.
Examples can include outsourced payroll processing, billing platforms, fund administrators, cloud transaction processing or third-party bookkeeping where information feeds the financial statements. An operationally important vendor whose service does not affect financial reporting may fall outside SA 402.
Start with the user entity, not with the service auditor’s report
A common mistake is to obtain a SOC-style or SAE 3402 report and assume the requirement is satisfied. SA 402 first requires the user auditor to understand the nature and significance of the outsourced service, the materiality of transactions or balances affected, the degree of interaction between the company and service organisation, and relevant contractual terms.
The auditor must also understand controls that remain with the company. These can include complementary user entity controls: controls the service organisation assumes the user entity will implement. A clean service-provider report cannot compensate for a relevant company-side control that was never designed or operated.
Type 1 vs Type 2: the practical difference
SA 402 distinguishes two kinds of service-auditor reports. A Type 1 report addresses the description and design of controls at the service organisation as at a specified date. A Type 2 report goes further: it addresses description, design and operating effectiveness over a specified period and includes the service auditor’s tests of controls and their results.
ICAI’s SAE 3402 provides the assurance framework for reports on controls at a service organisation and complements SA 402. Under SAE 3402, a Type 1 report does not express an opinion on operating effectiveness, while a Type 2 report covers operating effectiveness for the period in scope.
- Type 1: useful for understanding control description and design at a point in time.
- Type 2: potentially useful when the audit approach relies on service-organisation controls operating effectively during a period.
- Neither is automatic evidence for everything: the user auditor must evaluate whether scope, period, control objectives, tests and results are relevant to the assertions being audited.
When is a Type 1 report not enough?
If the audit approach depends on controls at the service organisation having operated effectively during the year, a Type 1 report generally cannot provide that evidence because it does not test operating effectiveness over a period. SA 402 says evidence may instead come from a Type 2 report, appropriate tests of controls performed at the service organisation, or another auditor performing those tests on the user auditor’s behalf.
Suppose a payroll processor calculates payroll for thousands of employees, posts payroll journals and generates payment files. If the audit strategy plans to rely on automated processor controls throughout the year, a point-in-time Type 1 report can explain design but cannot demonstrate year-long operating effectiveness. The evidence has to match the reliance being placed on the controls.
A practical SA 402 review workflow
- Map the outsourced process. Identify what the provider does, what data enters and leaves the system, and which balances, disclosures and assertions are affected.
- Identify retained company controls. Document approvals, reconciliations, interface checks, access reviews and complementary user entity controls.
- Read the report for scope, not just the opinion. Check covered services, control objectives, period or date covered, exceptions, tests performed and any subservice organisations.
- Match the report period to the audit period. A report covering only part of the financial year may require additional evidence. SA 402 specifically requires evaluation of the period covered and time elapsed since control testing.
- Assess the report as audit evidence. Consider the service auditor’s competence and independence as required by SA 402, the reporting standards used, and whether the tests performed are relevant to the financial-statement assertions.
- Test company-side controls where reliance requires it. If the report assumes the company performs a monthly interface reconciliation, evaluate whether that control exists and, where relevant, operates effectively.
- Address gaps directly. If understanding or evidence is insufficient, SA 402 permits routes such as obtaining further information, visiting the service organisation, performing procedures there or using another auditor.
What about subservice organisations?
A service provider may itself outsource part of processing. SA 402 requires attention to whether relevant subservice-organisation controls are included in or excluded from the service-auditor report. If a Type 1 or Type 2 report excludes a relevant subservice organisation, the user auditor must address those excluded services rather than assume the primary provider’s report covers them.
Worked example: outsourced payroll
Assume an Indian company outsources payroll calculation and payroll-journal generation. Management uploads master changes and attendance data; the processor calculates payroll; the company reviews a payroll summary and reconciles the payroll journal to the general ledger.
A Type 2 report may provide evidence on the processor’s access, change-processing and calculation controls for the period. The auditor should still confirm that the report covers the services actually used, review exceptions, check that the period aligns with the audit period, and test relevant company-side controls such as approval of master changes and payroll-to-ledger reconciliation. If a material subservice provider is excluded, that gap needs a separate audit response.
Common mistakes to avoid
- treating every outsourced vendor as automatically within SA 402;
- accepting Type 1 as evidence that controls operated effectively throughout the year;
- reading only the opinion and ignoring exceptions or test results;
- ignoring complementary user entity controls;
- using a report with a period gap without additional evidence; and
- missing relevant subservice organisations excluded from the report.
Practical takeaway
SA 402 works best when the auditor follows the transaction and control flow from the company into the service organisation and back. Understand what is outsourced, identify the financial-reporting risks, determine which controls remain with the company, and then decide what the service-auditor report actually proves. Type 1 is mainly about description and design at a point in time; Type 2 can provide evidence on operating effectiveness over a period. Any scope gap, period gap, control exception or missing complementary control still needs an audit response.