Hard1 markMultiple Choice
Area II: Risk AssessmentAUDService OrganizationsSOC Reports

CPA · Question 16 · Area II: Risk Assessment

An auditor is auditing a client that uses a service organization for payroll processing. The auditor obtains a SOC 1 Type 2 report. Which of the following is the auditor PRIMARILY interested in regarding this report?

Answer options:

A.

The service auditor's opinion on the fairness of the service organization's financial statements.

B.

The service auditor's opinion on the design implementation only.

C.

The service auditor's opinion on the operating effectiveness of controls at the service organization.

D.

The list of user control considerations that the client is not responsible for.

How to approach this question

Distinguish SOC 1 Type 1 (Design/Implementation at a point in time) vs Type 2 (Operating Effectiveness over a period).

Full Answer

C.The service auditor's opinion on the operating effectiveness of controls at the service organization.✓ Correct
The service auditor's opinion on the operating effectiveness of controls at the service organization.
A SOC 1 Type 2 report provides an opinion on the fairness of the presentation of the system AND the suitability of the design AND the operating effectiveness of the controls over a period of time. The user auditor needs the operating effectiveness opinion to reduce control risk and substantive testing.

Common mistakes

Confusing Type 1 and Type 2 reports.

Practice the full CPA AUD Practice Exam 5

78 questions · hints · full answers · grading

More questions from this exam