CISA Question of the Day: Relying on Service Auditor Reports

CISA exam practice question — CISA Question of the Day: Relying on Service Auditor Reports

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Auditing Process.

Question

An internal auditor is evaluating the controls of a client that uses a cloud provider for data processing. The client provides a recent SOC 2 Type II report covering the relevant period. What should the auditor do before reducing their own control testing based on the SOC report?

  • A. Evaluate the SOC report’s scope, period, opinion, and whether complementary user entity controls are required; then test the client’s implementation of those user controls as necessary before reducing audit procedures.
  • B. Accept the SOC 2 Type II report as sufficient evidence for the outsourced controls and reduce the client’s control testing without additional procedures.
  • C. Require the service auditor to perform a separate, client-specific engagement to test the client’s transactions and controls before any reliance is placed on the SOC report.
  • D. Replace the auditor’s control testing entirely with reliance on the service auditor’s work and obtain only a management representation about control implementation.
Show the answer and explanation

Correct answer: A. Evaluate the SOC report’s scope, period, opinion, and whether complementary user entity controls are required; then test the client’s implementation of those user controls as necessary before reducing audit procedures.

Option 0 is best because reliance on a SOC report requires evaluation of its relevance: scope, period, and the service auditor’s opinion, and identification of complementary user entity controls (CUECs). The auditor must obtain evidence that the client implemented those CUECs (by testing them or using other procedures) before reducing their own testing. Option 1 is wrong because accepting the report without assessing relevance and CUECs is insufficient. Option 2 is incorrect and impractical: the service auditor’s engagement scope cannot be retroactively extended to test client-specific transactions. Option 3 is inappropriate because replacing audit work solely with a management representation does not provide independent evidence.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.