Showing posts with label audit update. Show all posts
Showing posts with label audit update. Show all posts

Friday, June 3, 2011

An Overview of the New Service Organization Control Reports

Organizations that collect, retain, or process information on behalf of other organizations are known as service organizations.  Some of the most familiar types of service organizations widely used by companies are payroll processors, employee benefit plan administrators, and asset custodians. In recent years, there is also a growing reliance on providers of software as a service and cloud computing. Over the past decades, firms conducting audits of companies who use service organizations would rely on the organizations’ production of a Statement of Auditing Standard (SAS) 70 report. These reports would be prepared by the service organizations’ independent auditors and provided to any clients who relied on the service organizations’ information in preparing their own financial statements.
Beginning June 15, 2011, SAS 70 will be superseded by SSAE 16 for U.S. service organizations, which is similar to ISAE 3402 under IFRS.  The new reports are commonly referred to as Service Organization Control (SOC) Reports. There will be three types of SOC reports for companies to consider for issuance, summarized below:

SOC 1 Report – A review of user controls having an impact on clients’ financial reporting, SOC 1 reports will evaluate what is commonly known as ICOFR (internal controls over financial reporting). 

SOC 2 Report – Controls tested in a SOC 2 report will not be linked to financial reporting or financial statement assertions. Instead, SOC 2 reports will evaluate controls that fall under the AICPA Trust Services Principles and Criteria which include security, availability, processing integrity, confidentiality, and privacy.

Both SOC 1 and SOC 2 reports are similar to the former SAS 70 reports in that they list the service organization’s controls, how the auditor tested them, and the results of those tests. They will also include management’s assertions related to the controls tested. They are intended for restricted distribution to clients of the service organization.

SOC 3 Report – The audit work performed for a SOC 3 report is identical to that in a SOC 2, however the report issued merely summarizes management’s assertions and the auditor’s opinion, leaving out the detailed control descriptions and audit procedures. SOC 3 reports are intended to have unrestricted distribution, and those organizations receiving an unqualified opinion are permitted to display a seal on their website indicating the results of their SOC 3 report. 

As more and more organizations rely on service organizations for critical IT functions and processing of financial information, auditors should be familiar with the content of the new SOC reports and how they will impact their clients’ audits.

Friday, July 23, 2010

Center for Audit Quality Releases 2Q10 Checklist

In July, the Center for Audit Quality released their second quarter 2010 Accounting and Auditing Update. This has a been a particularly busy quarter for the FASB, so the checklist is a helpful way of tracking what regulatory guidance may have taken effect recently impacting you or your clients. There were also a few pronouncements from the SEC and PCAOB as well this past quarter. I've provided a summary of the updates below.

Recent FASB Accounting Standards Updates (ASU) include a March update on Foreign Currency Issues, specifically those related to investments in Venezuela. The Board is of the opinion that Venezuela has met the threshold for consideration as a highly inflationary economy, resulting in the recommendation that companies holding Venezuelan investments recognize valuation differences in the income statement rather than as a cumulative translation adjustment.

The FASB also amended a pronouncement related to oil and gas activities and subsequent event disclosures, as well as updated income tax guidance for the consideration of the recent Health Care and Education Reconciliation Act of 2010 and the Patient Protection and Affordable Care Act recently passed by Congress, as well as a pronouncement related to convertible debt issuances.

The PCAOB was less active than the FASB, issuing some changes to registered firms' reporting forms.

The SEC finalized their decision to require public companies and foreign private issuers that prepare their financial statements in accordance with US GAAP to provide their statements to the SEC using the interactive data format XBRL. Most companies have been preparing for this data conversion for some time.

An SEC extension for non-accelerated filers expired during the second quarter of 2010, requiring these companies to now provide auditor attestation reports in their annual reports for fiscal years ending on or after June 15, 2010. Lastly, the SEC made updates to their Compliance and Disclosure Interpretations and Disclosures Checklist during the past quarter, which are available at their website.

The Center for Audit Quality Second Quarter Checklist also notes that several key financial reporting matters are to be considered by the FASB in the near future, including those relating to pooled loans accounted for as receivables, revenue recognition, accruals for casino jackpot liabilities, financial services insurance, stock compensation, derivatives and hedging, and software revenue. It looks like the latter half of 2010 will be even busier than the second quarter.

Stay up to date on recent accounting pronouncements by subscribing to the Center for Audit Quality. Even if all of the updates do not apply to you or your clients, you are likely to come across some important information you should know about. To read the entire second quarter update, visit http://www.complianceweek.com/s/documents/CAQAlert2Q210.pdf. To subscribe to the Center for Audit Quality, visit http://www.thecaq.org/.