• No results found

Reports on Controls at Outside Service Organizations 8

4.54 When a fund uses a service organization, such as an outside transfer agent, subtransfer agent, or recordkeeping agent, transactions that affect the fund's financial statements are subjected to controls that are, at least in part, physically and operationally separate from the fund. The significance of the con-trols of the service organization to those of the fund depends on the nature of the services provided by the service organization, primarily the nature and materi-ality of the transactions it processes for the fund and the degree of interaction between its activities and those of the fund. For example, if the fund initiates

8AU section 324.57–.60brequires a service auditor to inquire of management about subsequent events.

For more information on AU section 324areaders should refer to the Audit Guide entitledService Organizations: Applying SAS No. 70, as Amended, which includes illustrative control objectives as well as interpretations that address the responsibilities of service organizations and service auditors with respect to forward-looking information and the risk of projecting evaluations of controls to future periods. The Guide also clarifies that the use of a service auditor's report should be restricted to existing customers and is not meant for potential customers.

bParagraphs .57 through .60 of AU section 324 can be found in AICPAProfessional Stan-dards and PCAOB StanStan-dards and Related Rules.

aSee footnote a in paragraph 4.21.

transactions and the service organization executes and does the accounting processing of those transactions, there is a high degree of interaction between the activities of the fund and those at the service organization. In these circum-stances, it may be practicable for the user organization to implement effective controls over those transactions. However, if the service organization initiates, executes, and does the accounting processing of the user organization's trans-actions, there is a lower degree of interaction, and it may not be practicable for the fund to implement effective internal controls over those transactions.

4.55 AU section 320 (AICPA, PCAOB Standards and Related Rules), es-tablishes requirements that apply for an integrated audit. Refer to AU section 320.218 (AICPA,PCAOB Standards and Related Rules), regarding the use of service organizations.

4.56 AU section 319.02, Consideration of Internal Control in a Financial Statement Audit (AICPA, Professional Standards, vol. 1; AICPA, PCAOB Stan-dards and Related Rules), states that an auditor should obtain an understand-ing of an entity's internal control sufficient to plan the audit by performunderstand-ing procedures to understand the design of controls relevant to an audit of finan-cial statements and determining whether they have been placed in operation.

In obtaining this understanding, the auditor considers how an entity's use of information technology (IT)9and manual procedures may affect controls rele-vant to the audit. AU section 319.02 (AICPA,Professional Standards, vol. 1), further states that the auditor then assesses control risk for the assertions em-bodied in the account balance, transaction class, and disclosure components of the financial statements.*AU section 319.02 (AICPA,PCAOB Standards and Related Rules), further states that the auditor then assesses control risk for the relevant assertions embodied in the account balance, transaction class, and disclosure components of the financial statements. Regardless of the assessed level of control risk, the auditor should perform substantive procedures for all relevant assertions related to all significant accounts and disclosures in the financial statements.

4.57 If a fund uses a service organization, certain controls and records of the service organization may be relevant to the fund's ability to record, pro-cess, summarize, and report financial data in a manner consistent with the assertions in the entity's financial statements. AU section 324.03–.10 (AICPA, Professional Standards, vol. 1; AICPA, PCAOB Standards and Related Rules), describes factors that an auditor should consider in determining whether to obtain information about controls at a service organization. AU section 324a provides guidance on the auditor's assessment of control risk in such circum-stances. AU section 324.14cstates that, if the auditor plans to assess control

9Information technology (IT) encompasses automated means of originating, processing, storing, and communicating information, and includes recording devices, communication systems, computer systems (including hardware and software components and data), and other electronic devices. An entity's use of IT may be extensive; however, the auditor is primarily interested in the entity's use of IT to initiate, record, process, and report transactions or other financial data.

*In March 2006, the ASB issued eight SASs related to risk assessment. It is anticipated that to implement the SASs appropriately, many firms will have to make significant revisions to their audit methodologies and train their personnel accordingly. The SASs are effective for audits of financial statements for periods beginning on or after December 15, 2006; earlier application is permitted.

Refer to the Preface of this Guide for more information. This Guide will be updated to reflect these eight standards closer to their effective date.

aSee footnote a in paragraph 4.21.

c Paragraph .14 of AU section 316 can be found in AICPAProfessional Standards and PCAOB Standards and Related Rules.

risk below the maximum for assertions that are affected by activities of the service organization, the auditor should evaluate the operating effectiveness of controls at the service organization relevant to those assertions by obtaining a service auditor's report on the controls placed in operation and tests of operat-ing effectiveness, obtainoperat-ing an agreed-upon procedures report that addresses those controls, or performing tests of controls at the service organization.

4.58 Although a service auditor's report on controls placed in operation and tests of operating effectiveness may provide a basis for assessing control risk below the maximum, it does not permit the auditor to assess the level of control risk so low as to eliminate the need to perform substantive tests for the fund's capital accounts and transactions.

4.59 AU section 324a provides guidance on the auditor's considerations in using a service auditor's report. To evaluate a service auditor's report, the auditor should follow that guidance. The auditor may wish to discuss with the service auditor the scope and results of the service auditor's work for a better understanding of the procedures and conclusions.

4.60 The auditor should not refer to the report of the service auditor as a basis, in part, for an opinion on the fund's financial statements. The service auditor's report is used in the audit, but the service auditor is not responsible for examining any portion of the financial statements as of any specific date or for any specific period.

aSee footnote a in paragraph 4.21.

Chapter 5