What does complementary user entity controls mean on the CPA exam?
Complementary user entity controls. Controls a service organization assumes its customers are running. If the customer does not run them, the service organization's controls do not achieve their objective, which is why they are listed in the report.
Defined against AICPA DC Section 200.
Which CPA exam sections use complementary user entity controls?
Complementary user entity controls appears in the ISC section of the CPA exam.
Other names for complementary user entity controls
CUEC
Related terms
- user entities: The customers of a service organization, whose own financial reporting or systems depend on the service organization's controls.
- application controls: Controls built into one business process or system, such as a validity check on an input field or a three-way match.
- general controls: Controls over the IT environment as a whole -- access, change management, operations -- that everything else depends on.
- service organization: A third party whose processing affects a user entity's financial reporting, such as a payroll bureau or a claims processor.
- user auditor: The auditor of an entity that uses a service organization.
- carve-out method: Excludes a subservice organization's control objectives and controls from both the description and the scope of the service auditor's report.