CORAA

SA 402 — Audit Considerations Relating to an Entity Using a Service Organisation

Issued by ICAI AASB · Risk Assessment

What an auditor must do when the client's processing or controls sit with an outside service organisation such as a payroll processor or a shared services centre.

Objective

To obtain an understanding of the nature and significance of the services provided by the service organisation and their effect on the user entity's internal control, and to design and perform responsive audit procedures.

Key requirements

  • Understand the services provided and how they affect the user entity's internal control
  • Evaluate the design and implementation of relevant controls at the user entity
  • Use a service auditor's report, either on design and implementation (type 1) or also on operating effectiveness (type 2), after checking its date, scope and the service auditor's competence
  • Consider complementary user entity controls that the report assumes the client has in place
  • Consider subservice organisations and whether they are carved out or included

Typical procedures

  • Obtain the latest service auditor's report and read the control objectives and exceptions
  • Map the report's controls to the client's relevant assertions
  • Test the complementary user entity controls at the client
  • Where no report exists, perform procedures at the service organisation or alternative procedures

Common pitfalls

  • Relying on a type 1 report as if it showed operating effectiveness
  • Report period not covering the whole financial year, with no bridging procedures
  • Ignoring exceptions and carved-out subservice organisations

Related standards

SA 315SA 330SA 500

SA 402 in practice

SA 402 sits in the Risk Assessment phase of the audit. The Standards on Auditing are issued by the ICAI Auditing and Assurance Standards Board (AASB) and deemed to be prescribed by the Central Government under Section 143(10) of the Companies Act 2013. Compliance with SAs is mandatory for every audit conducted by a Chartered Accountant in India.

For authoritative text, refer to the ICAI AASB Compendium of Standards on Auditing at icai.org.

Free downloads · Working formats for SA 402

Take the working versions with you

Editable, letterhead-ready formats that put SA 402 into practice — built from the ICAI working-paper set, free to download.

Internal Financial Controls →

And when you want SA 402 executed and documented automatically — your first audit on CORAA is free.

SA 402 — frequently asked

What is SA 402 (Audit Considerations Relating to an Entity Using a Service Organisation)?

SA 402 — Audit Considerations Relating to an Entity Using a Service Organisation — is a Standard on Auditing issued by the ICAI Auditing and Assurance Standards Board. What an auditor must do when the client's processing or controls sit with an outside service organisation such as a payroll processor or a shared services centre. To obtain an understanding of the nature and significance of the services provided by the service organisation and their effect on the user entity's internal control, and to design and perform responsive audit procedures.

Is SA 402 mandatory in India?

Yes. Standards on Auditing are deemed to be prescribed under Section 143(10) of the Companies Act 2013, and ICAI members must comply with them in every audit of historical financial information. Non-compliance must be justified and can attract professional consequences in peer review, NFRA inspection, and disciplinary proceedings.

What should the working papers show for SA 402?

Documentation sufficient for an experienced auditor with no previous connection to the audit to understand what was done and why (SA 230). For SA 402 in the risk assessment phase, that means evidencing: Understand the services provided and how they affect the user entity's internal control; Evaluate the design and implementation of relevant controls at the user entity; Use a service auditor's report, either on design and implementation (type 1) or also on operating effectiveness (type 2), after checking its date, scope and the service auditor's competence.

← Previous
SA 330 — The Auditor's Responses to Assessed Risks
Next →
SA 450 — Evaluation of Misstatements Identified During the Audit