Medium1 markMultiple Choice
Area I: Information SystemsCloud ComputingSaaSAudit EvidenceSOC 2

CPA · Question 14 · Area I: Information Systems

A company uses a SaaS-based CRM. The auditor wants to verify that the company's data is backed up. The SaaS provider's contract states they perform daily backups. What is the MOST appropriate evidence for the auditor to request?

Answer options:

A.

Screenshots of the company's internal server backup logs.

B.

A written representation from the company's IT manager.

C.

The SaaS provider's source code for the backup script.

D.

A SOC 2 Type II report from the SaaS provider covering the Availability criteria.

How to approach this question

When auditing a cloud vendor (SaaS), you generally cannot go onsite. You rely on Third-Party Assurance reports (SOC reports).

Full Answer

D.A SOC 2 Type II report from the SaaS provider covering the Availability criteria.✓ Correct
D
For SaaS vendors, the most appropriate and reliable evidence is a SOC 2 report (specifically covering Availability) which provides an independent auditor's opinion on the design and operating effectiveness of the provider's backup controls.

Common mistakes

Thinking the client can back up SaaS data themselves (sometimes they can, but the question asks about the provider's obligation).

Practice the full CPA ISC Practice Exam

82 questions · hints · full answers · grading

More questions from this exam