Hard1 markMultiple Choice
Area II: Risk AssessmentAUDService OrganizationsInternal Control

CPA · Question 66 · Area II: Risk Assessment

An auditor is auditing the financial statements of a nonissuer. The auditor uses a service organization for payroll. The auditor receives a SOC 1 Type 1 report. Which of the following is a limitation of this report?

Answer options:

A.

It does not describe the service organization's system.

B.

It does not include an opinion from the service auditor.

C.

It does not provide evidence of the operating effectiveness of controls.

D.

It cannot be used to obtain an understanding of internal control.

How to approach this question

SOC 1 Type 1 vs Type 2. Type 1 = Design (Can I trust the plan?). Type 2 = Operating Effectiveness (Did they follow the plan?). Only Type 2 allows you to reduce control risk.

Full Answer

C.It does not provide evidence of the operating effectiveness of controls.✓ Correct
A SOC 1 Type 1 report addresses the fairness of the presentation of the system and the suitability of the design of controls as of a specific date. It does NOT test operating effectiveness, so the user auditor cannot use it to reduce control risk (rely on controls).

Common mistakes

Thinking Type 1 allows control reliance.

Practice the full CPA AUD Practice Exam 2

78 questions · hints · full answers · grading

More questions from this exam